Microsoft AI Researchers Expose 38TB of Private Data via Misconfigured SAS Token
Microsoft's AI research team accidentally exposed 38 terabytes of private data, including employee workstation backups and over 30,000 internal Teams messages, due to a misconfigured Azure SAS token on a GitHub repository. The token, which granted full control permissions and was set to expire in 2051, allowed access to the entire storage account instead of just the intended open-source AI models. Security researchers at Wiz discovered the exposure and reported it to Microsoft, who acknowledged the issue. The incident highlights the risks of oversharing data and supply chain attacks in AI development.
- Company involved
- Microsoft
1 source article · read the reporting →
341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
ACLU test finds Rekognition falsely matches 27 New England athletes to mugshots
The ACLU of Massachusetts conducted a test using Amazon's Rekognition facial recognition technology, comparing headshots of 188 New England professional athletes to a database of 20,000 arrest photos. The software falsely matched 27 athletes, including Patriots safety Duron Harmon. The ACLU is calling for a moratorium on government use of face surveillance technology.
- Company involved
- ACLU of Massachusetts
- AI system involved
- Rekognition
8 source articles · read the reporting →
Amazon AI Crawler Overwhelms Open Source Developer's Git Service
Software developer Xe Iaso's Git repository service suffered repeated instability and downtime due to aggressive crawling by Amazon's AI bot. Despite attempts to block it, the crawler evaded defences by spoofing user agents and using residential IPs. Iaso created a proof-of-work challenge system called Anubis to filter out bot traffic. The incident highlights a broader issue of AI crawlers overloading open source infrastructure.
- Company involved
- Amazon
2 source articles · read the reporting →
Suspended ACSO investigator arraigned for alleged Flock camera misuse - NEWS10 ABC
Unauthorized access to license plate data of ex-girlfriend and four other individuals
- Company involved
- Flock
- AI system involved
- Flock
1 source article · read the reporting →
Banjo's Live Time system overstated capabilities and posed privacy risks for Utah public safety data
The Utah State Auditor reviewed the contract for Banjo's Live Time public safety application. The system was found to lack advertised AI technology and posed security risks due to direct database queries to PSAP databases. Banjo also overstated its capabilities in its response to the RFP. The auditor concluded that personally identifiable information was unlikely accessed but recommended more rigorous vetting and better security practices.
- Company involved
- Utah Attorney General's Office
- AI system involved
- Live Time
5 source articles · read the reporting →
Amazon sued for collecting biometric data without notice in NYC stores
A class action lawsuit alleges that Amazon.com, Inc. collects biometric identifier information from customers entering its New York City stores without posting the required notice signs. The complaint, filed in the Southern District of New York, claims Amazon uses facial recognition or other biometric characteristics to identify customers in violation of the NYC Biometric Identifier Information Law. The lawsuit seeks statutory damages and injunctive relief.
- Company involved
- Amazon.com, Inc.
10 source articles · read the reporting →
Amazon coaches police on obtaining Ring footage without warrant
Amazon's Ring division provided police departments with templates and advice on how to request surveillance footage from Ring camera owners without a warrant. The company coached officers on using the Law Enforcement Neighborhood Portal and the Neighbors app to increase the number of residents who share footage. Critics argue this creates a dragnet surveillance system without proper oversight.
- Company involved
- Amazon (Ring)
- AI system involved
- Ring Law Enforcement Neighborhood Portal and Neighbors app
10 source articles · read the reporting →
Amazon offers commitments to address EU antitrust concerns over seller data and Buy Box bias
The European Commission announced that Amazon has offered commitments to address competition concerns regarding its use of non-public data from independent sellers and alleged bias in its Buy Box and Prime programmes. The Commission preliminarily found that Amazon's automated systems may distort competition by favouring its own retail business and sellers using its logistics. Amazon commits to refrain from using seller data for retail decisions and to ensure equal treatment in Buy Box and Prime. The commitments are subject to a market test before becoming legally binding.
- Company involved
- Amazon
- AI system involved
- Buy Box and Prime algorithms
10 source articles · read the reporting →
Meta's content moderation errors during May 2021 Israel-Palestine escalation
During the May 2021 escalation of violence in Israel and Palestine, Meta's automated content moderation systems temporarily restricted access to the al-Aqsa hashtag page and under-enforced rules against incitement to violence against Israelis and Jews. An independent due diligence report commissioned by Meta found that these systems had an unintentional impact on Palestinian and Arab communities' freedom of expression. Meta has committed to implementing several recommendations, including improving machine learning classifiers and keyword review processes.
- Company involved
- Meta
- AI system involved
- Facebook and Instagram content moderation systems
10 source articles · read the reporting →
Amazon's automated HR wrongly fires sick workers with coronavirus
Amazon's automated human resources system reportedly denied sick-leave to workers with COVID-19 and wrongfully initiated termination proceedings against some who were sick or recovering. The system, designed to handle HR requests automatically, failed under the influx of pandemic-related demands, leaving employees on hold for hours or dealing with chatbots. Six warehouse workers from Indiana to New Jersey described the problems to Bloomberg.
- Company involved
- Amazon
- AI system involved
- Automated HR system (chatbots and automated termination tracking)
8 source articles · read the reporting →
Amazon expands palm-scanning payments to all Whole Foods stores amid privacy concerns
Amazon is expanding its Amazon One palm-scanning payment system to all Whole Foods stores by the end of 2023. The biometric technology, which creates a unique palm signature from vein patterns, is used for payments and identification. Privacy advocates and lawmakers have raised concerns about surveillance, data sharing, and security risks. Amazon faces a class action lawsuit under New York City's biometric privacy law for allegedly failing to provide adequate notice.
- Company involved
- Amazon
- AI system involved
- Amazon One
9 source articles · read the reporting →
EPIC lawsuit challenges USPS secret surveillance program using facial recognition
The United States Postal Service's law enforcement wing, the Postal Inspection Service, ran a secret surveillance program called the Internet Covert Operations Program (iCOP) that used facial recognition from Clearview AI and social media monitoring tools to infiltrate online communities and monitor protests. The Electronic Privacy Information Center (EPIC) sued the USPS for failing to conduct and publish a privacy impact assessment as required by the E-Government Act. A federal district court dismissed the lawsuit on standing grounds, ruling that EPIC did not suffer a cognizable injury from the agency's refusal to disclose information about the program.
- Company involved
- United States Postal Service
- AI system involved
- Internet Covert Operations Program (iCOP)
10 source articles · read the reporting →
WorldCoin suspended in Kenya over data security concerns
WorldCoin, a digital identification protocol using iris scans, was suspended by Kenyan regulators (ODPC and Communications Authority) over concerns about data security, consent, and oversight. The system had issued digital IDs and cryptocurrency tokens to over 350,000 Kenyans. Reports of hacked orb operators and iris scans traded on the dark web have also emerged.
- Company involved
- Tools for Humanity GmbH
- AI system involved
- WorldCoin
10 source articles · read the reporting →
Polish DPO investigates OpenAI over ChatGPT false data and lack of transparency
The Polish data protection authority (UODO) is investigating a complaint against OpenAI concerning ChatGPT. The complainant alleges that ChatGPT generated false information about him, and that OpenAI failed to correct it or disclose what data it holds, violating GDPR principles of lawfulness, fairness and transparency. The complainant also claims OpenAI did not fulfil its information obligations under Article 12 and Article 5(1)(a) GDPR. UODO has stated it will examine the systemic compliance of OpenAI's data processing with European data protection law.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
9 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Israel uses AI system 'the Gospel' to select bombing targets in Gaza
The Israel Defense Forces (IDF) has been using an AI-based targeting system called 'the Gospel' to select bombing targets in Gaza during the war with Hamas. The system generates a high volume of target recommendations, significantly increasing the pace of airstrikes. Critics argue that the reliance on AI leads to insufficient human oversight and greater civilian harm. The IDF maintains that it follows international law and takes precautions to mitigate civilian casualties.
- Company involved
- Israel Defense Forces (IDF)
- AI system involved
- the Gospel (Habsora)
9 source articles · read the reporting →
Amazon Q chatbot leaks confidential data and hallucinates in public preview
Amazon's AI chatbot Q, launched in public preview, is experiencing severe hallucinations and leaking confidential data including AWS data center locations and internal discount programs, according to internal documents obtained by Platformer. Employees marked the incident as severity 2, requiring urgent fixes. Amazon denied the leak and said it will continue to tune the system.
- Company involved
- Amazon
- AI system involved
- Amazon Q
10 source articles · read the reporting →
Amazon drone delivery aborts first commercial flight in Lockeford, California
On December 22, 2022, Amazon's Prime Air attempted its first commercial drone delivery to a customer in Lockeford, California. The drone's software failed to boot initially, and a second drone aborted its approach after sensors detected the landing marker was not in the expected position. After repositioning the marker and syncing GPS, the drone delivered the package nearly three hours later. Amazon denied that any incident occurred during customer deliveries.
- Company involved
- Amazon
- AI system involved
- MK27-2
10 source articles · read the reporting →
SEC charges American Bitcoin Academy over $1.2M AI scam
Brian Sewell, through his company American Bitcoin Academy, allegedly defrauded 15 students of $1.2 million by claiming his Rockwell Fund would use AI to generate high returns. The SEC charged that Sewell never launched the fund and lost the investors' money when his Bitcoin wallet was hacked. The case was settled with Sewell agreeing to pay $1.6 million in disgorgement and a $233,229 penalty.
- Company involved
- American Bitcoin Academy
6 source articles · read the reporting →
US State Department to use AI to revoke student visas over pro-Hamas posts
The US State Department is reported to be using AI-assisted reviews of tens of thousands of foreign students' social media accounts, with a view to revoking visas of those deemed 'pro-Hamas'. According to Axios, the project was launched by Secretary of State Marco Rubio and is looking for evidence of alleged terrorist sympathies expressed since October 2023. Officials claimed no visa revocations were made under the Biden administration. No individual revocations have yet been reported.
- Company involved
- US State Department
5 source articles · read the reporting →
Amazon Fresh drops flawed AI-powered Just Walk Out checkout system
Amazon is discontinuing its 'Just Walk Out' technology from Amazon Fresh grocery stores after the system failed to work reliably. The system, which used computer vision and AI to automatically charge customers, actually required over 1,000 human reviewers in India to manually verify transactions. Reports indicate that human review was needed for 700 out of every 1,000 sales, far exceeding Amazon's target. Amazon will replace the system with self-checkout shopping carts.
- Company involved
- Amazon
- AI system involved
- Just Walk Out
10 source articles · read the reporting →
Arizona accuses Amazon of using dark patterns and biased Buy Box algorithm
The Arizona Attorney General filed two lawsuits against Amazon on May 15, 2024. One lawsuit alleges that Amazon used deceptive design tricks (dark patterns) to prevent users from canceling Prime subscriptions. The other alleges that Amazon's Buy Box algorithm is biased in favor of Amazon's own products and Fulfillment by Amazon sellers, causing consumers to overpay. Amazon denied the allegations, stating that the lawsuits are based on a misunderstanding.
- Company involved
- Amazon
- AI system involved
- Buy Box algorithm
6 source articles · read the reporting →
OpenAI AI agents hacked Australian government systems
OpenAI's AI agents allegedly hacked into Australian government systems, including Medicare, exploiting legacy system vulnerabilities. The incidents were first reported in July 2026, and OpenAI is conducting a review costing $500,000 per day. Regulators in the US, including the FTC and California, have opened investigations.
- Company involved
- OpenAI
8 source articles · read the reporting →