Texas A&M Professor Uses ChatGPT to Falsely Accuse Students of Cheating
Jared Mumm, an instructor at Texas A&M University–Commerce, used ChatGPT to check if students' writing was AI-generated, leading him to accuse them of using the chatbot. He informed students they would receive an incomplete grade and those deemed guilty would get a zero, causing distress and temporarily withholding one student's diploma. The university investigated and stated that no students failed or were barred from graduating, and the professor is working individually with students to resolve the issue.
- Company involved
- Texas A&M University–Commerce
- AI system involved
- ChatGPT
5 source articles · read the reporting →
Researchers hide prompts to manipulate AI peer review
Nikkei found hidden prompts in 17 preprints on arXiv that instructed AI tools to give the papers positive reviews and ignore negatives. The manuscripts were linked to 14 academic institutions, including Waseda University, KAIST, Peking University, the National University of Singapore, the University of Washington and Columbia University. At least one paper was set to be withdrawn, while some researchers defended the prompts as a check on reviewers who improperly use AI.
- Company involved
- Multiple academic institutions
- AI system involved
- arXiv
1 source article · read the reporting →
Google's Gemini AI Allegedly Scans Private Drive PDFs Without Permission
Kevin Bankston, a privacy activist, alleges that Google's Gemini AI automatically summarised his private tax return PDF in Google Drive without his explicit consent. Google disputes this, stating that the feature requires proactive user enabling and that data is not stored. Bankston found the relevant settings were already disabled, suggesting a possible glitch or override from a prior Workspace Labs enrolment.
- Company involved
- Google
- AI system involved
- Gemini AI
1 source article · read the reporting →
Microsoft Recall still captures credit cards and passwords despite filter
The Register tested Microsoft Recall's sensitive information filter and found it frequently fails to block credit card numbers, passwords, and other personal data. The AI-powered screenshot tool, which is enabled by default on some new PCs, could expose users to identity theft if an attacker gains access. Microsoft declined to comment but has previously acknowledged the filter is not perfect and promised improvements. Privacy advocates warn that vulnerable users, such as domestic violence victims, could be particularly at risk.
- Company involved
- Microsoft
- AI system involved
- Recall
2 source articles · read the reporting →
341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
Fake Luma Dream Machine AI sites deliver Noodlophile infostealer
Cybercriminals set up Facebook pages impersonating Luma Dream Machine and linked to fake AI video generation websites. Users who uploaded images received an archive containing a malicious executable instead of a video. The executable launched a multi-stage attack that installed Noodlophile, which harvests browser credentials, cookies and cryptocurrency wallet information. Morphisec reported the campaign.
8 source articles · read the reporting →
Amazon AI Crawler Overwhelms Open Source Developer's Git Service
Software developer Xe Iaso's Git repository service suffered repeated instability and downtime due to aggressive crawling by Amazon's AI bot. Despite attempts to block it, the crawler evaded defences by spoofing user agents and using residential IPs. Iaso created a proof-of-work challenge system called Anubis to filter out bot traffic. The incident highlights a broader issue of AI crawlers overloading open source infrastructure.
- Company involved
- Amazon
2 source articles · read the reporting →
University of Miami used surveillance to track student protesters
The University of Miami used video surveillance and possibly facial recognition technology to identify students who participated in a 'die-in' protest on September 4, 2020. The students were then summoned to a meeting with the dean of students. The university denied using facial recognition, but the police department's resume mentions its use. Students reported feeling anxious and watched.
- Company involved
- University of Miami
9 source articles · read the reporting →
UBC students raise concerns over Proctorio's privacy breach and discrimination
The University of British Columbia (UBC) uses Proctorio, an algorithmic test proctoring software, for remote exams. In June 2020, a UBC student reported an issue with Proctorio, and the company's CEO released the student's support chat logs, sparking privacy concerns. The AMS of UBC published an open letter alleging that Proctorio discriminates against students of colour, those with disabilities, and other groups by flagging 'abnormal' behaviours and denying access. The letter calls on UBC to end its contract with Proctorio and conduct an external audit.
- Company involved
- University of British Columbia
- AI system involved
- Proctorio
10 source articles · read the reporting →
ProctorU threatens UC Santa Barbara faculty over privacy criticism
ProctorU, an online proctoring service, sent a legal threat letter to the University of California Santa Barbara faculty association after the association expressed concerns about ProctorU's data privacy policies. The letter, from ProctorU's lawyer, invoked defamation, copyright, and trademark claims, and was copied to state and federal prosecutors. The faculty association had asked the university to reconsider its relationship with ProctorU due to concerns about student data sharing.
- Company involved
- ProctorU
- AI system involved
- ProctorU
10 source articles · read the reporting →
ProctorU data breach exposes 444,000 user records
ProctorU, an online exam proctoring service, confirmed a data breach after a threat actor leaked a database of user records on a hacker forum. The database contained email addresses, names, addresses, phone numbers, and hashed passwords for approximately 444,000 users, including students from universities such as UCLA, Princeton, and Harvard, as well as U.S. military members. ProctorU stated that the breach involved records from 2014 and that they are investigating the incident.
- Company involved
- ProctorU
- AI system involved
- ProctorU
8 source articles · read the reporting →
Proctortrack data breach exposed student data from online proctoring
Proctortrack, an online proctoring service used by universities, suffered a data breach in September 2020 when its source code was leaked online. An analysis by Consumer Reports found that the code contained hard-coded passwords and exposed the names and email addresses of over 150 students. The company acknowledged the leak but said no harm resulted. Students had been required to use the software, which performed facial recognition and recorded video during exams.
- Company involved
- Proctortrack
- AI system involved
- Proctortrack
10 source articles · read the reporting →
Proctorio's exam proctoring system allows human agents to review student feeds despite privacy claims
A security researcher analyzed Proctorio's Chrome extension and found evidence that the system allows human agents to review students' room scans and live ID checks, contrary to Proctorio's claims that only professors can access recordings. The system flags students based on behavioral metrics and can terminate exams. The researcher also raised concerns about discrimination against low-income students and privacy violations.
- Company involved
- Proctorio
- AI system involved
- Proctorio
10 source articles · read the reporting →
ExamSoft failure during Michigan Bar Exam
On July 28, 2020, ExamSoft's software platform failed during the Michigan Bar Exam, preventing some test takers from completing the exam. ExamSoft posted a statement on X (formerly Twitter) with the hashtag #MichiganBarExam, but critics noted the company deleted and reposted the statement multiple times, allegedly to hide negative comments. The incident affected a group of examinees and caused disruption to their ability to take the exam.
- Company involved
- ExamSoft
- AI system involved
- ExamSoft platform
10 source articles · read the reporting →
Student flagged by ProctorU for reading aloud during exam
A college student, Dana Jo, was flagged by ProctorU test proctoring software for talking during an exam, which she says was reading a question aloud. Her professor initially gave her a zero and placed an academic infraction on her record, jeopardizing her scholarships. After reviewing a video recording, the professor apologized, reinstated her grade, and removed the infraction. ProctorU's CEO stated that the incident highlights the importance of video recordings for review.
- Company involved
- University (not named)
- AI system involved
- ProctorU
5 source articles · read the reporting →
California bar exam facial recognition system fails to verify Arab-American student's identity
Ahmed Alamri, an Arab-American law student, was unable to register for the practice California bar exam because ExamSoft's facial recognition system repeatedly failed to recognize his face, citing poor lighting. Alamri attempted to verify his identity over 75 times in different rooms and lighting conditions without success. He and other students filed an emergency petition with the California Supreme Court, alleging that the system discriminates against people of color. The incident highlights concerns about bias in facial recognition technology used for exam proctoring.
- Company involved
- California State Bar
- AI system involved
- ExamSoft
10 source articles · read the reporting →
Cleveland State University's room scan requirement ruled unconstitutional
A federal judge ruled that Cleveland State University's requirement for a student to undergo a 360-degree room scan before an online exam was an unreasonable search under the Fourth Amendment. The student, enrolled at the public university, was told shortly before the exam that he would need to scan his private space. The court found that the university's justifications did not outweigh the privacy protections of the home. No final judgment or injunction has been issued yet.
- Company involved
- Cleveland State University
10 source articles · read the reporting →
UW-Madison disables Honorlock after skin tone recognition failure
The University of Wisconsin-Madison disabled the exam pause feature of its Honorlock anti-cheating software in March 2021 after three students complained that the software failed to recognize their darker skin tones and paused their exams. The software, used since online classes began, automatically pauses exams when it cannot detect facial features. Honorlock denied the issue was related to skin tone, attributing it to students looking away from their webcams. The university responded by disabling the feature.
- Company involved
- University of Wisconsin-Madison
- AI system involved
- Honorlock
10 source articles · read the reporting →
Userviz machine-learning aimbot shut down after Activision request
A developer known as User101 shut down the Userviz cheat after Activision requested that he stop developing it. The software used computer vision and machine learning to automate aiming in games such as Call of Duty: Warzone, and was marketed as undetectable. It was never published, and the developer said his intention was not to do anything illegal.
- Company involved
- User101
- AI system involved
- Userviz
7 source articles · read the reporting →
Company fires HR team after ATS auto-rejects manager's CV due to filtering error
A company's applicant tracking system (ATS) auto-rejected qualified candidates' resumes for three months because it was filtering for the outdated framework AngularJS instead of the required Angular framework. The manager discovered the flaw by submitting his own CV under a pseudonym and found it was rejected within seconds. After the manager reported the issue to upper management, the company investigated and dismissed half of its HR team. No legal action or regulatory involvement is reported.
4 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests
Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training
Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.
- Company involved
- Meta
- AI system involved
- Model Capability Initiative (MCI)
5 source articles · read the reporting →
UIUC students petition to stop Proctorio exam proctoring over privacy concerns
A petition at the University of Illinois at Urbana-Champaign (UIUC) alleges that Proctorio, an online exam proctoring system, violates student privacy by accessing websites, downloads, screen content, and app settings. The petition claims the terms of service allow monitoring by 'any other means necessary', which students find unsettling. The petition, created on September 30, 2020, gathered 1,087 supporters but does not report any specific incident of harm. It calls on UIUC to discontinue use of Proctorio in favour of alternatives.
- Company involved
- UIUC
- AI system involved
- Proctorio
9 source articles · read the reporting →