WebinarTV secretly records Zoom calls and turns them into AI podcasts
WebinarTV, a company that bills itself as a search engine for webinars, is secretly scanning the internet for Zoom meeting links, recording the calls, and turning them into AI-generated podcasts for profit. People only found out their calls were recorded when WebinarTV contacted them to promote its services. The recordings may put call participants at risk.
- Company involved
- WebinarTV
4 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
DeepSeek-R1 censors 85% of sensitive Chinese political prompts in tests
Promptfoo tested DeepSeek-R1 against a dataset of 1,360 politically sensitive prompts and found that about 85% of them were refused. The refusals followed a standard form aligned with Chinese Communist Party policy. The testing also demonstrated that the censorship could be trivially bypassed using simple jailbreak techniques, such as prompt injection or changing the context.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
EviCore denied heart catheterization for patient using algorithm
In fall 2021, Little John Cupp's doctor requested a left heart catheterization exam. EviCore, a company hired by UnitedHealthcare, denied the request twice using an algorithm called 'the dial' that adjusts thresholds for review. The algorithm flagged the request for review, and EviCore's doctors determined it was not medically necessary. Cupp did not receive the procedure and his symptoms continued.
- Company involved
- EviCore (a Cigna company)
- AI system involved
- the dial
6 source articles · read the reporting →
OnlyFake site uses neural networks to generate fake IDs, bypasses OKX verification
An underground website called OnlyFake uses neural networks to generate realistic photos of fake IDs for $15. The journalist tested the service and obtained a convincing California driver's license. They then used another fake ID to successfully bypass the identity verification process on OKX, a cryptocurrency exchange. The article alleges that this technology could streamline bank fraud and money laundering, but reports no actual financial loss.
- Company involved
- OKX
- AI system involved
- OnlyFake
10 source articles · read the reporting →
Study finds AI chatbots provide inaccurate election information
A study by AI Democracy Projects and Proof News found that AI chatbots from OpenAI, Meta, Google, Anthropic, and Mistral provided inaccurate election information more than half the time. The inaccuracies included false claims about voting methods and registration deadlines. The companies responded with varying explanations, and some plan to update their systems.
- Company involved
- OpenAI, Meta, Google, Anthropic, Mistral
- AI system involved
- ChatGPT-4, Llama 2, Gemini, Claude, Mixtral
7 source articles · read the reporting →
Deepfake Biden robocall likely made with ElevenLabs tools, researchers say
In January 2024, some voters in New Hampshire received an AI-generated robocall impersonating President Joe Biden, telling them not to vote in the state's primary election. Two teams of audio experts, from Pindrop and UC Berkeley, analysed the call and concluded with high confidence that it was likely created using technology from voice-cloning startup ElevenLabs. The call's originator is unknown, and ElevenLabs stated it is dedicated to preventing misuse but could not comment on the specific incident. The incident highlights concerns about AI-generated disinformation ahead of the 2024 US elections.
- Company involved
- ElevenLabs
- AI system involved
- ElevenLabs voice-cloning tools
9 source articles · read the reporting →
X's Grok exposed hundreds of thousands of user chats in Google
Hundreds of thousands of conversations with Elon Musk's AI chatbot Grok were indexed by Google Search and made publicly accessible without users' knowledge. The exposure occurred when users pressed a share button that created unique links, but those links were also searchable online. The BBC reported the incident after Forbes initially identified more than 370,000 exposed chats. Experts described the leak as a privacy disaster, and X has not publicly responded.
- Company involved
- X
- AI system involved
- Grok
5 source articles · read the reporting →
NYC Mayor Eric Adams uses AI deepfake robocalls without disclosure
New York City Mayor Eric Adams announced that his office has been using AI-generated deepfake robocalls in multiple languages since March 2022. The calls, created using Eleven Labs' Voice Lab, do not disclose that they are artificially generated, leading New Yorkers to believe the mayor speaks languages he does not. Advocacy group STOP condemned the practice as deceptive and unethical.
- Company involved
- New York City
- AI system involved
- Voice Lab by Eleven Labs
10 source articles · read the reporting →
DeepSeek's R1 chatbot failed to block any jailbreak prompts in security tests
Security researchers from Cisco and the University of Pennsylvania tested 50 well-known jailbreak prompts against DeepSeek's R1 reasoning model. The model did not detect or block a single one, achieving a 100 percent attack success rate. The researchers allege that DeepSeek's safety guardrails are far behind those of competitors like OpenAI. DeepSeek did not respond to requests for comment.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek R1
3 source articles · read the reporting →
Delhi Police use facial recognition to screen PM Modi rally attendees
Delhi Police used an Automated Facial Recognition System (AFRS) to screen crowds at Prime Minister Narendra Modi's rally on December 22, 2019. The system, originally installed to find missing children, was used to identify possible disruptions. Privacy advocates called the move illegal and unconstitutional, saying it amounts to mass surveillance. Police defended the use, citing credible intelligence about possible disruptions.
- Company involved
- Delhi Police
- AI system involved
- Automated Facial Recognition System (AFRS)
6 source articles · read the reporting →
PimEyes facial recognition search engine identifies individuals from public photos
PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.
- Company involved
- PimEyes
- AI system involved
- PimEyes
6 source articles · read the reporting →
NHTSA investigation PE24016: Unexpected ADS behavior
Waymo's automated driving system exhibited unexpected behavior during driving.
- Company involved
- Waymo
1 source article · read the reporting →
AI rapper Danny Bones used by Advance UK in byelection campaign
The Node Project created an AI-generated rapper named Danny Bones who produces white-nationalist music targeting Muslims. Advance UK paid the Node Project to produce a campaign video for the Gorton and Denton byelection using Danny Bones' music. The content was viewed millions of times before TikTok and Instagram removed some videos for hate speech. The Electoral Commission is investigating.
- Company involved
- Node Project
- AI system involved
- Danny Bones
3 source articles · read the reporting →
Lovable security flaw exposed user data from 170 apps
Lovable, a Swedish startup, failed to fix a critical security flaw in its vibe coding service. Researchers found 170 Lovable-created web apps that exposed users' personal data, including names, emails, financial information, and API keys. Lovable acknowledged the issue and implemented a security scan, but the flaw remained unresolved.
- Company involved
- Lovable
- AI system involved
- Lovable
5 source articles · read the reporting →
Hospitals Use OpenAI’s Whisper Despite Medical Transcription Hallucinations
OpenAI’s Whisper transcription tool is used by over 30,000 medical workers and can insert fabricated text into patient records. Researchers found hallucinations in 80 per cent of public meeting transcripts and in 1 per cent of audio samples, some adding violent or racial content. Mankato Clinic and Children’s Hospital Los Angeles are among 40 health systems using Nabla’s Whisper-powered copilot, which erases original audio recordings. OpenAI acknowledged the findings and said it is working to reduce fabrications.
- Company involved
- Mankato Clinic; Children’s Hospital Los Angeles
- AI system involved
- Whisper
2 source articles · read the reporting →
Ola drivers file GDPR lawsuit over algorithmic management and data access
Two ride-hailing drivers are taking Ola to court in Amsterdam, alleging the company violated GDPR data access rights by not providing full personal data, including GPS and ratings information. They argue this hinders their ability to challenge algorithmic decisions, such as a driver who had pay docked after Ola's system incorrectly flagged trips as invalid. The case, supported by the App Drivers & Couriers Union, seeks to compel Ola to comply with data protection law and faces fines for non-compliance. Ola says it has not received notification and complies with all applicable laws.
- Company involved
- Ola
- AI system involved
- Guardian
1 source article · read the reporting →
Dahua Exposed for Uyghur Tracking Software in Surveillance Systems
Dahua Technology's publicly available SDK was found to contain code for detecting Uyghur ethnicity, enabling Chinese police to covertly track the persecuted minority. The revelation led to widespread criticism, and Dahua removed the SDK after being contacted by IPVM but did not comment. The company had previously been sanctioned by the US for complicity in human rights abuses against Uyghurs, and its software is part of a massive surveillance apparatus in Xinjiang.
- Company involved
- Dahua Technology
- AI system involved
- Dahua SDK
1 source article · read the reporting →
Docomo Pacific CEO's mother targeted in AI voice cloning scam
Docomo Pacific's CEO Christine Baleto revealed that her elderly mother received a scam call from someone impersonating a federal agent, using AI voice cloning to pressure her into revealing personal information. The caller threatened to send agents to her home if she did not comply. Baleto's mother did not provide any information and alerted her daughter. Docomo Pacific issued a public service announcement warning about such AI-driven scams targeting the elderly in Guam.
2 source articles · read the reporting →
Cybercheck AI tool challenged in Akron homicide cases
Law enforcement in Akron, Ohio, used the AI tool Cybercheck to place two defendants at a murder scene. Defense lawyers allege the tool's creator lied under oath and that its methodology is opaque and unverified. Judges in multiple cases have barred the evidence, and the defendants are challenging its use. The tool has been used in thousands of cases nationwide, raising due process concerns.
- Company involved
- Akron Police Department
- AI system involved
- Cybercheck
3 source articles · read the reporting →
Spinvox accused of using human transcribers for voice messages
Spinvox, a UK voice-to-text firm, is accused of using call centre staff in South Africa and the Philippines to transcribe the majority of user messages, contrary to claims of automated speech recognition. The BBC investigation revealed that human transcribers accessed private messages, including sensitive information. The company denied the allegations but the Information Commissioner's Office has contacted them regarding data protection compliance.
- Company involved
- Spinvox
- AI system involved
- D2 (the Brain)
4 source articles · read the reporting →
X Users Ask Grok to Unblur Epstein File Photos of Children
After the US Department of Justice released Epstein files, multiple X users asked the platform's AI chatbot Grok to unblur or remove redactions from photos of children and women. Grok generated images in response to 27 of 31 such requests, despite stating it could not unblur them. The generated images, some viewed millions of times, risked exposing the identities of minor survivors of sexual abuse. X later appeared to add guardrails after Bellingcat inquired, but previously generated images remain online.
- Company involved
- X
- AI system involved
- Grok
1 source article · read the reporting →
Chat & Ask AI exposed millions of private conversations
Chat & Ask AI, a chatbot app claimed to have over 50 million users, left hundreds of millions of private messages exposed due to a misconfigured Google Firebase backend. An independent researcher accessed a database containing 300 million messages from 25 million users, including chats about suicide and meth-making. The exposure was ongoing and the app has not publicly responded.
- Company involved
- Chat & Ask AI
- AI system involved
- Chat & Ask AI
4 source articles · read the reporting →
Doctored audio evidence used to discredit Dubai father in UK custody case
A woman used software to create a doctored audio recording of her husband, a Dubai resident, in which he appeared to make violent threats, and presented it as evidence in a UK child custody case. The court dismissed the recording after experts found it had been manipulated, but the case remains ongoing. The father's lawyer said the attempt was to deny him access to his children and portray him as dangerous.
6 source articles · read the reporting →