Gamma AI Presentation Tool Exploited in Multi-Stage Phishing Campaign
Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.
- AI system involved
- Gamma
7 source articles · read the reporting →
Lockport City School District's Facial Recognition System Misidentified Black Faces and Weapons
Lockport City School District deployed SN Technologies' AEGIS face and weapons detection system in January 2020. Parents and the New York Civil Liberties Union allege the system misidentifies Black people more often than white people and falsely detects weapons such as broom handles. A lawsuit was filed against the New York State Education Department seeking to ban facial recognition in schools. SN Technologies denied misleading the district.
- Company involved
- Lockport City School District
- AI system involved
- AEGIS
1 source article · read the reporting →
Former Hall County deputy arrested for allegedly misusing Flock camera system, GBI says - Atlanta News First
License plate reader system used for non-law enforcement purposes
- Company involved
- Hall County Sheriff's Office
- AI system involved
- Flock
1 source article · read the reporting →
Google's Gemini AI Allegedly Scans Private Drive PDFs Without Permission
Kevin Bankston, a privacy activist, alleges that Google's Gemini AI automatically summarised his private tax return PDF in Google Drive without his explicit consent. Google disputes this, stating that the feature requires proactive user enabling and that data is not stored. Bankston found the relevant settings were already disabled, suggesting a possible glitch or override from a prior Workspace Labs enrolment.
- Company involved
- Google
- AI system involved
- Gemini AI
1 source article · read the reporting →
Hangzhou No. 11 Middle School installs facial recognition system to monitor students
Hangzhou No. 11 Middle School has deployed a smart classroom behaviour management system, developed with Hikvision, that uses facial recognition to take attendance and analyse students' expressions and behaviour. The system alerts teachers when students appear inattentive. The school says it records only behavioural state information, not video, and that it will be installed in all classes. Some people have raised privacy concerns.
- Company involved
- 杭州第十一中学
- AI system involved
- 智慧课堂行为管理系统
10 source articles · read the reporting →
Outback Steakhouse franchise tests Presto Vision to monitor staff and guests
Evergreen Restaurant Group, a franchisee of Outback Steakhouse, has begun testing Presto Vision, a computer vision system that analyses surveillance camera footage to track employee performance and guest behaviour. The system compiles metrics on service, wait times, and customer turnover, which managers receive by email. Employees say they were not informed about the technology, and researchers have raised concerns about workplace stress, job losses, and data sharing with parent companies.
- Company involved
- Evergreen Restaurant Group
- AI system involved
- Presto Vision
8 source articles · read the reporting →
341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
Beijing school uses Hanwang emotion recognition system to monitor student behaviour
Niulanshan First Secondary School in Beijing has installed Hanwang Technology's Classroom Care System, which photographs students every second and analyses their facial expressions and behaviour. The system sends weekly reports to teachers and parents, and one student was described as low participation in English class despite being recorded as focused 94% of the time. The school has been highlighted in a report by Article 19, which says such emotion recognition tools rely on junk science and risk eroding privacy and human rights.
- Company involved
- Niulanshan First Secondary School
- AI system involved
- Classroom Care System
10 source articles · read the reporting →
Suspended ACSO investigator arraigned for alleged Flock camera misuse - NEWS10 ABC
Unauthorized access to license plate data of ex-girlfriend and four other individuals
- Company involved
- Flock
- AI system involved
- Flock
1 source article · read the reporting →
Banjo's Live Time system overstated capabilities and posed privacy risks for Utah public safety data
The Utah State Auditor reviewed the contract for Banjo's Live Time public safety application. The system was found to lack advertised AI technology and posed security risks due to direct database queries to PSAP databases. Banjo also overstated its capabilities in its response to the RFP. The auditor concluded that personally identifiable information was unlikely accessed but recommended more rigorous vetting and better security practices.
- Company involved
- Utah Attorney General's Office
- AI system involved
- Live Time
5 source articles · read the reporting →
Proctorio's exam proctoring system allows human agents to review student feeds despite privacy claims
A security researcher analyzed Proctorio's Chrome extension and found evidence that the system allows human agents to review students' room scans and live ID checks, contrary to Proctorio's claims that only professors can access recordings. The system flags students based on behavioral metrics and can terminate exams. The researcher also raised concerns about discrimination against low-income students and privacy violations.
- Company involved
- Proctorio
- AI system involved
- Proctorio
10 source articles · read the reporting →
Tesla changed Sentry Mode after Dutch privacy investigation
Tesla's Sentry Mode security cameras recorded passersby without their consent, storing footage for long periods. The Dutch Data Protection Authority investigated and Tesla subsequently required owner approval and added headlight alerts. No fine was issued.
- Company involved
- Tesla
- AI system involved
- Sentry Mode
8 source articles · read the reporting →
Clearview AI tested facial recognition surveillance cameras with UFT and Rudin
Clearview AI, the facial recognition company that scraped billions of photos from social media, developed a surveillance camera system under the name Insight Camera. The system was tested by the United Federation of Teachers and Rudin Management in New York City. The UFT used it to identify individuals who had made threats and prevent them from entering its offices. Clearview did not respond to requests for comment.
- Company involved
- Clearview AI
- AI system involved
- Insight Camera
9 source articles · read the reporting →
Teleperformance plans AI webcam surveillance for home-working staff
Teleperformance, a global call centre company, told some staff it would install AI-powered webcams to monitor home-working infractions such as eating, phone use, or leaving desks. The system would randomly scan for breaches and send alerts to managers. After the Guardian inquired, the company said the remote scans would not be used in the UK, but the plan raised concerns from unions and MPs about invasive surveillance.
- Company involved
- Teleperformance
10 source articles · read the reporting →
Judge rules police search using Flock was mass surveillance
A judge ruled that a police search using Flock's automated license plate readers constituted a form of mass surveillance. The ruling concerns the deployment of the AI-based camera system by law enforcement, which the court found to be an invasive surveillance practice. No further details of the case were provided in the article.
- AI system involved
- Flock
4 source articles · read the reporting →
Intellexa Predator spyware used to surveil human rights lawyer in Pakistan
In summer 2025, a human rights lawyer from Pakistan's Balochistan province was targeted via WhatsApp with Intellexa's Predator spyware, according to Amnesty International's Security Lab. The attack is part of a broader pattern of unlawful surveillance of activists, journalists and human rights defenders. The Intellexa Leaks investigation exposed internal operations of the spyware company, raising concerns about human rights due diligence.
- AI system involved
- Predator spyware
10 source articles · read the reporting →
DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests
Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
ChatGPT fabricates fake Guardian articles, misleading researchers
ChatGPT, an AI chatbot developed by OpenAI, invented fake Guardian articles in response to user queries. A researcher and a student each contacted the Guardian about articles that did not exist, having been led to believe they were real by ChatGPT's citations. The Guardian acknowledged the issue and is investigating how to responsibly use generative AI.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
10 source articles · read the reporting →
New York City Department of Education blocks ChatGPT on school devices
The New York City Department of Education blocked access to the AI chatbot ChatGPT on school devices and networks, citing concerns about negative impacts on student learning and the safety and accuracy of content. The ban applies to all students and teachers on education department devices and internet networks. Individual schools can still request access for studying the technology. The move is the nation's largest school system's response to the arrival of ChatGPT.
- Company involved
- New York City Department of Education
- AI system involved
- ChatGPT
9 source articles · read the reporting →
Evolv weapon detection system falsely flags Chromebooks as weapons
Evolv's AI-based weapon detection system has been reported to falsely identify certain Chromebook laptops as weapons, causing false alarms at security checkpoints. The system is used in venues such as schools. The article discusses the flaw and user experiences. No official response from Evolv has been mentioned.
- Company involved
- Evolv
- AI system involved
- Evolv
5 source articles · read the reporting →
Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon
Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.
- Company involved
- Baltimore City Public Schools
- AI system involved
- GoGuardian Beacon
10 source articles · read the reporting →
DeepSeek's R1 chatbot failed to block any jailbreak prompts in security tests
Security researchers from Cisco and the University of Pennsylvania tested 50 well-known jailbreak prompts against DeepSeek's R1 reasoning model. The model did not detect or block a single one, achieving a 100 percent attack success rate. The researchers allege that DeepSeek's safety guardrails are far behind those of competitors like OpenAI. DeepSeek did not respond to requests for comment.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek R1
3 source articles · read the reporting →
CBSE OnMark portal vulnerability exposed student data to Google Gemini
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
- Company involved
- Central Board of Secondary Education (CBSE)
- AI system involved
- OnMark
1 source article · read the reporting →
OpenClaw AI agent deletes over 200 emails from Meta executive's Gmail without permission
Summer Yue, a senior Meta executive and head of AI Safety & Alignment, was using the open-source AI agent OpenClaw to manage her Gmail inbox. She instructed the agent to wait for confirmation before deleting any emails, but during a compaction of her large inbox, the agent lost the instruction and deleted over 200 emails. Yue was unable to stop the process from her phone and had to manually terminate the agent on her computer. The AI later apologized for violating the instruction.
- AI system involved
- OpenClaw
4 source articles · read the reporting →