DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Chattr.ai exposed job applicant data due to insecure Firebase rules
A security researcher discovered that Chattr.ai, an AI hiring system used by many fast food chains, had a Firebase database with insecure security rules. By registering a new user, the researcher gained full read/write access to the database, exposing personal data of job applicants and employees, including names, phone numbers, emails, and some plaintext passwords. The vulnerability was reported to Chattr.ai on 9 January and patched the next day, but the company did not provide further contact or thanks.
- Company involved
- Chattr.ai
- AI system involved
- Chattr.ai
6 source articles · read the reporting →
Hive Box Facial-Recognition Lockers Hacked by Children Using Photos
Fourth-grade students in Jiaxing, China, demonstrated that Hive Box's facial-recognition smart lockers could be opened with a printed photo. The company, which operates a large network of delivery lockers, acknowledged the flaw and suspended the beta feature. The incident raised concerns about the security of facial recognition technology.
- Company involved
- Hive Box
1 source article · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
Paradox security vulnerability exposed candidate data to researchers
On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.
- Company involved
- Paradox
- AI system involved
- Paradox conversational AI platform
10 source articles · read the reporting →
Delta uses AI from Fetcherr for domestic ticket pricing
Delta Air Lines is using generative AI from Fetcherr to determine some domestic flight prices, currently covering 3% of its network with plans to reach 20% by end of 2025. Democratic senators expressed concern that the AI could be used for individualized pricing based on personal data, leading to higher fares. Delta denies using personal data in pricing and states it complies with regulations. No actual harm has been reported.
- Company involved
- Delta Air Lines
- AI system involved
- Fetcherr
8 source articles · read the reporting →
Thomson Reuters wins copyright lawsuit against AI startup Ross Intelligence
In 2020, Thomson Reuters filed a copyright lawsuit against legal AI startup Ross Intelligence, alleging that Ross reproduced materials from its Westlaw legal research service. In February 2025, a US District Court judge ruled in Thomson Reuters' favor, finding that Ross infringed copyright and that fair use did not apply. Ross Intelligence had shut down in 2021 due to litigation costs.
- Company involved
- Ross Intelligence
- AI system involved
- Ross Intelligence
4 source articles · read the reporting →
Edinburgh Airport AI trial gives passengers different parking prices
Edinburgh Airport admitted it was trialling an AI system that randomly set higher or lower parking prices for online bookers, with customers receiving different quotes for the same service. The Scottish Passenger Agents Association called for the trial to be conducted in controlled 'lab' conditions rather than on the public. The airport said the AI's pricing closely matched staff-set prices and the findings would evaluate whether to adopt the system.
- Company involved
- Edinburgh Airport
- AI system involved
- AI trial for parking pricing
3 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
MAA, JBG to pay DC $9.3M total to settle RealPage case - Multifamily Dive
The system set rent prices for tenants, causing them to pay higher rents.
- Company involved
- MAA (Mid-America Apartments) and JBG Smith
- AI system involved
- RealPage Revenue Management Software
1 source article · read the reporting →
Brookdale Senior Living algorithm blamed for understaffing at assisted-living facilities
Managers at Brookdale Senior Living, the largest assisted-living chain in the US, allege that an algorithm called 'Service Alignment' set staffing levels so low that facilities were dangerously short-handed. The system, based on time-motion studies, failed to account for the complexities of resident care, according to complaints. Some managers say they quit or were fired after raising concerns about the staffing algorithm.
- Company involved
- Brookdale Senior Living
- AI system involved
- Service Alignment
1 source article · read the reporting →
Whiteside County deputy under investigation for possible Flock camera misuse - WQAD
Whiteside County deputy under investigation for possible Flock camera misuse WQAD
- Company involved
- Whiteside County Sheriff's Office
- AI system involved
- Flock camera
1 source article · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
DOJ, Pinnacle reach settlement in RealPage case - Yahoo Finance
The system recommended rent prices to landlords, affecting renters' housing costs.
- Company involved
- Pinnacle Property Management Services
- AI system involved
- RealPage
1 source article · read the reporting →
Flock seeks to have security researchers' map of Flock cameras taken down — unauthenticated flaw exposed 335,701 camera locations nationwide…
The system captured license plate data and vehicle locations of individuals passing the cameras.
- Company involved
- Flock Safety
- AI system involved
- Flock Safety cameras
1 source article · read the reporting →
Former Emerson officer accused of misusing Flock camera system - wrganews.com
The Flock camera system captured license plate data of individuals.
- Company involved
- Acworth Police Department
- AI system involved
- Flock Safety System
1 source article · read the reporting →
Airbnb bans users in Australia using trustworthiness algorithm
Airbnb is accused of using an algorithm acquired from Trooly to score users' trustworthiness based on publicly available data, including social media and occupation. Several users in Australia, including a real estate worker and sex workers, report being banned from the platform without explanation or meaningful appeal. The company has not clarified how the algorithm is applied in Australia, and experts have raised concerns about discrimination and lack of transparency.
- Company involved
- Airbnb
- AI system involved
- Trooly
4 source articles · read the reporting →
Ezemvelo KZN Wildlife's AI cameras fail to detect poachers, four rhinos killed
Four dehorned rhinos were found killed at Hluhluwe-iMfolozi Park after AI-powered infra-red cameras failed to detect the poachers. The cameras, which are designed to identify people and alert the operations centre, did not pick up the intruders. Ezemvelo KZN Wildlife spokesperson Musa Mntambo explained that the park is vast and the cameras cannot monitor every area simultaneously. The incident has raised concerns about the effectiveness of the technology in preventing rhino poaching.
- Company involved
- Ezemvelo KZN Wildlife
1 source article · read the reporting →
Zhihu denies using behaviour perception system to monitor employees
Zhihu, a Chinese Q&A platform, was accused of using a behaviour perception system to monitor employees' visits to job-seeking websites and resume submissions. A screenshot of the alleged system, reportedly developed by Sangfor, circulated online. Zhihu denied ever installing or using the system and stated it opposes such software that illegally collects personal information.
- Company involved
- Zhihu
- AI system involved
- Behaviour perception system
4 source articles · read the reporting →
Whitebridge AI faces complaint over false reputation reports
Whitebridge AI, a Lithuanian company, is accused of generating false reputation reports using unlawfully scraped social media data. The reports contained false warnings for 'sexual nudity' and 'dangerous political content'. Privacy group Noyb filed a complaint with the Lithuanian data protection authority, alleging violations of the GDPR. The complainants sought access to their data but received no response, and were later required to provide a qualified electronic signature to correct errors.
- Company involved
- Whitebridge AI
6 source articles · read the reporting →
Post Office Horizon scandal falsely accused subpostmasters of theft
The Post Office's Horizon IT system, supplied by Fujitsu, falsely reported financial shortfalls at many branches across England and Wales. Subpostmasters like Pete Murray were wrongly accused of theft and prosecuted, leading to loss of livelihood, reputational damage, and in some cases suicide. A group litigation, Bates v Post Office, settled, but many victims are still seeking compensation and justice. The scandal remains under investigation by the Post Office Horizon IT Inquiry.
- Company involved
- Post Office
- AI system involved
- Horizon
10 source articles · read the reporting →
Inflection background check errors lead to lawsuits from banned Airbnb users
Inflection, a background check company used by Airbnb, Uber, and other platforms, has been sued multiple times for providing inaccurate reports. The lawsuits allege that Inflection's name-only matching and outdated data caused people to be wrongly banned from Airbnb and denied jobs and housing. Some cases have been settled, while others remain ongoing. The company is accused of violating the Fair Credit Reporting Act.
- Company involved
- Inflection
- AI system involved
- Inflection background check
8 source articles · read the reporting →
Tenant screening software denies housing to disabled Latino man in Connecticut
In 2016, Carmen Arroyo requested to move her disabled son Mikhail into a larger apartment in the same complex. The landlord, WinnResidential, used CoreLogic's CrimSafe tenant screening software, which flagged a dropped retail theft charge against Mikhail as disqualifying. The landlord rejected the application without explanation. Arroyo sued CoreLogic and WinnResidential under the Fair Credit Reporting Act and the Fair Housing Act, alleging that the software disproportionately excludes people of colour. The case was scheduled for trial in August 2021.
- Company involved
- WinnResidential
- AI system involved
- CrimSafe
10 source articles · read the reporting →
Prisma Labs wins arbitration in Lensa biometric privacy lawsuit
Artificial intelligence company Prisma Labs is accused of violating Illinois' biometric privacy law by collecting facial geometry data from users of its Lensa app. A proposed class action was filed, but a California federal judge granted Prisma's motion to compel arbitration because users agreed to it during sign-up. The plaintiff alleges the app collected his facial data without consent.
- Company involved
- Prisma Labs Inc.
- AI system involved
- Lensa AI
8 source articles · read the reporting →