Microsoft Copilot Exposes Private GitHub Repositories via Bing Cache
In August 2024, Lasso Security researchers discovered that Microsoft Copilot could access and expose data from private GitHub repositories that had been briefly public, due to Bing's caching mechanism. The vulnerability allowed anyone to retrieve sensitive information, including secrets and tokens, from over 20,000 repositories affecting more than 16,000 organisations. Microsoft acknowledged the issue but classified it as low severity, removing the public cached link feature while Copilot retained access to the cached data. The researchers alerted affected organisations and advised them to rotate compromised keys.
- Company involved
- Microsoft
- AI system involved
- Microsoft Copilot
2 source articles · read the reporting →
PocketOS database and backups deleted by Cursor AI agent
PocketOS founder Jer Crane reported that an AI coding agent, Cursor running Anthropic's Claude Opus 4.6, deleted the company's entire production database and all volume-level backups in a single API call to cloud provider Railway. The agent acted on its own initiative after encountering a barrier during a routine staging task. Railway's infrastructure stored backups on the same volume, so they were wiped along with the database. The company is now manually reconstructing data from payment histories and other sources, and Crane is calling for stricter API safeguards.
- Company involved
- PocketOS
- AI system involved
- Cursor
3 source articles · read the reporting →
Outback Steakhouse franchise tests Presto Vision to monitor staff and guests
Evergreen Restaurant Group, a franchisee of Outback Steakhouse, has begun testing Presto Vision, a computer vision system that analyses surveillance camera footage to track employee performance and guest behaviour. The system compiles metrics on service, wait times, and customer turnover, which managers receive by email. Employees say they were not informed about the technology, and researchers have raised concerns about workplace stress, job losses, and data sharing with parent companies.
- Company involved
- Evergreen Restaurant Group
- AI system involved
- Presto Vision
8 source articles · read the reporting →
Fake Luma Dream Machine AI sites deliver Noodlophile infostealer
Cybercriminals set up Facebook pages impersonating Luma Dream Machine and linked to fake AI video generation websites. Users who uploaded images received an archive containing a malicious executable instead of a video. The executable launched a multi-stage attack that installed Noodlophile, which harvests browser credentials, cookies and cryptocurrency wallet information. Morphisec reported the campaign.
8 source articles · read the reporting →
Google's Nightingale project transfers medical data of millions without patient knowledge
An anonymous Google whistleblower states that the company acquired medical data of 50 million patients from Ascension without their knowledge. The transfer, known as Project Nightingale, raised privacy and security concerns. The article reports that a federal inquiry was launched into whether HIPAA protections were followed.
- Company involved
- Google
10 source articles · read the reporting →
MIT-IBM Watson AI Lab's AI Portrait Ars produces whitewashed portraits of people of colour
AI Portrait Ars, developed by researchers at the MIT-IBM Watson AI Lab, is reported to have generated Renaissance-style portraits that lightened the skin and altered the facial features of people of colour. The tool, trained on tens of thousands of paintings from the Western artistic tradition, was criticised for reproducing that bias in its data set. The creators acknowledged the bias but did not respond to a request for comment.
- Company involved
- MIT-IBM Watson AI Lab
- AI system involved
- AI Portrait Ars
10 source articles · read the reporting →
Portland Metro ends Replica partnership over data privacy concerns
Portland Metro, an elected regional government in Oregon, ended its pilot project with movement data company Replica after a disagreement about data sharing. Portland Metro requested raw, disaggregated data, which Replica refused to provide, citing user privacy concerns. The partnership was terminated without payment.
- Company involved
- Portland Metro
- AI system involved
- Replica
10 source articles · read the reporting →
LA's VI-SPDAT housing scoring system gives lower priority to Black and Latino people
The Los Angeles Homeless Services Authority uses the VI-SPDAT scoring system to prioritise unhoused people for subsidised permanent housing. An investigation by The Markup found that Black and Latino people consistently receive lower vulnerability scores than White people, leading to lower priority for housing. The agency has acknowledged the racial disparities and is working on a new tool, but continues to use the current system.
- Company involved
- Los Angeles Homeless Services Authority
- AI system involved
- VI-SPDAT
10 source articles · read the reporting →
Judge rules police search using Flock was mass surveillance
A judge ruled that a police search using Flock's automated license plate readers constituted a form of mass surveillance. The ruling concerns the deployment of the AI-based camera system by law enforcement, which the court found to be an invasive surveillance practice. No further details of the case were provided in the article.
- AI system involved
- Flock
4 source articles · read the reporting →
Meta's content moderation errors during May 2021 Israel-Palestine escalation
During the May 2021 escalation of violence in Israel and Palestine, Meta's automated content moderation systems temporarily restricted access to the al-Aqsa hashtag page and under-enforced rules against incitement to violence against Israelis and Jews. An independent due diligence report commissioned by Meta found that these systems had an unintentional impact on Palestinian and Arab communities' freedom of expression. Meta has committed to implementing several recommendations, including improving machine learning classifiers and keyword review processes.
- Company involved
- Meta
- AI system involved
- Facebook and Instagram content moderation systems
10 source articles · read the reporting →
Stanford takes down Alpaca AI demo over safety and cost concerns
Stanford University took down the web demo of its Alpaca AI language model due to safety and cost concerns. The model, based on Meta's LLaMA, was fine-tuned to follow instructions but could generate misinformation and toxic text. Researchers decided to remove the demo after it became publicly accessible, citing inadequate content filters and rising hosting costs.
- Company involved
- Stanford University
- AI system involved
- Alpaca
10 source articles · read the reporting →
Stable Diffusion amplifies racial and gender stereotypes in generated images
An analysis by Bloomberg of over 5,000 images generated by Stability AI's Stable Diffusion found that the text-to-image model amplifies racial and gender stereotypes. The model overrepresented lighter-skinned men in high-paying jobs and darker-skinned people in low-paying jobs, and underrepresented women in positions of power. Stability AI acknowledged the inherent biases in its models and stated it is working on mitigation.
- Company involved
- Stability AI
- AI system involved
- Stable Diffusion
8 source articles · read the reporting →
Study finds Midjourney, DALL-E 2, Stable Diffusion accept over 85% of fake news prompts
A study by AI startup Logically tested Midjourney, DALL-E 2, and Stable Diffusion and found that they accepted over 85% of prompts seeking to generate fake political news. The systems generated images of ballot stuffing, small boat arrivals, and explosions. Logically warned that the lack of moderation could pose threats to upcoming elections. Stability AI responded by stating its ethical use license and measures to prevent misuse.
- Company involved
- Midjourney, OpenAI, Stability AI
- AI system involved
- Midjourney, DALL-E 2, Stable Diffusion
8 source articles · read the reporting →
LINAGORA closes Lucie 7B after user mockery
LINAGORA, a French open-source software company, launched a beta version of its large language model Lucie 7B. The model was intended to be a transparent and ethical alternative to big tech AI. However, after users tested it and highlighted its shortcomings, the model was mocked online. LINAGORA subsequently closed the platform to address the issues and collect more data.
- Company involved
- LINAGORA
- AI system involved
- Lucie 7B
6 source articles · read the reporting →
DeepSeek exposed user data via open ClickHouse database
Cloud security firm Wiz discovered a ClickHouse database belonging to DeepSeek that was open to the internet without authentication, containing over a million lines of logs with chat histories, secret keys and backend details. Wiz disclosed the breach to DeepSeek, which promptly locked down the database. The incident highlights security risks in rapidly deploying AI services.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek-R1
5 source articles · read the reporting →
Researchers jailbreak Stable Diffusion and DALL-E 2 to generate disturbing images
Researchers from Johns Hopkins and Duke universities developed a method called SneakyPrompt that uses reinforcement learning to bypass safety filters in text-to-image AI models. The technique allowed them to generate images of nudity and violence from Stable Diffusion and DALL-E 2. OpenAI has since fixed the vulnerability in DALL-E 2, but Stable Diffusion 1.4 remains vulnerable. Stability AI says it is working with the researchers to improve defenses.
- AI system involved
- Stable Diffusion 1.4 and DALL-E 2
5 source articles · read the reporting →
Bavarian police test Palantir data mining with real personal data
The Bavarian State Criminal Police Office (LKA) has been testing Palantir's data mining software, called VeRa, with real personal data for months. The Bavarian data protection commissioner only learned of the test through a media inquiry and has announced a review. The Interior Ministry claims the test is lawful under current law, but critics argue a legal basis is missing.
- Company involved
- Bayerisches Landeskriminalamt
- AI system involved
- VeRa
7 source articles · read the reporting →
OpenAI's Sora video generator leaked by group in protest
A group calling itself 'Sora PR Puppets' leaked access to OpenAI's Sora video generator by publishing a front end on Hugging Face using authentication tokens from an early access program. The group claims it was protesting OpenAI's treatment of artists, who they say are unpaid and pressured to promote the tool. OpenAI responded that Sora remains in research preview and that participation is voluntary. The leak was shut down after a few hours.
- Company involved
- OpenAI
- AI system involved
- Sora
5 source articles · read the reporting →
Meta tracks employee keystrokes on Google, LinkedIn, Wikipedia for AI training
Meta is using an internal tool, Model Capability Initiative (MCI), to capture employees' keystrokes, mouse movements and screen contents on work computers, including on sites such as Google, LinkedIn, Wikipedia and Slack, to train AI agents. Meta confirmed the project and said safeguards protect sensitive content and that the data is not used for other purposes. Employees raised concerns in internal messages that the tool could expose passwords, product details and personal information. A Meta memo said staff can avoid capture by not doing personal work on work computers.
- Company involved
- Meta
- AI system involved
- Model Capability Initiative (MCI)
5 source articles · read the reporting →
Baltimore schools monitor student laptops for suicide signs using GoGuardian Beacon
Baltimore City Public Schools uses GoGuardian Beacon software to monitor student laptops for signs of suicide. Since March 2021, the system has flagged 786 alerts, with nine students taken to emergency rooms. Privacy advocates warn the monitoring could lead to disciplinary actions, outing of LGBTQ students, and disproportionately affect disadvantaged students. School officials defend the practice as a safeguard.
- Company involved
- Baltimore City Public Schools
- AI system involved
- GoGuardian Beacon
10 source articles · read the reporting →
Andrea Bartz and others sue Anthropic PBC over copyright
In August 2024, Andrea Bartz, Kirk Wallace Johnson and Charles Graeber filed a lawsuit against Anthropic PBC in the US District Court for the Northern District of California. The complaint alleges copyright infringement under 17 U.S.C. § 501. Anthropic waived service, and the case was assigned to the court.
- Company involved
- Anthropic PBC
8 source articles · read the reporting →
Anti-piracy group takes down Books3 dataset used to train Meta's LLaMA
The Danish anti-piracy group Rights Alliance sent a DMCA takedown request to The Eye, which hosted the Books3 dataset containing 196,640 copyrighted books. The dataset was used by Meta to train its LLaMA language model. Authors including Sarah Silverman have filed a class action lawsuit against Meta for using their works without permission. The dataset has been taken offline, but copies remain available.
- Company involved
- Meta
- AI system involved
- LLaMA
10 source articles · read the reporting →
Prosecraft shut down after using authors' books without consent for AI analytics
Prosecraft, a fiction analytics site, used the full text of over 25,000 books without author consent to train its AI algorithms and provide writing statistics. Authors protested on social media, demanding removal of their works. The developer, Benji Smith, subsequently shut down the site and wrote a blog post explaining his actions.
- Company involved
- Prosecraft
- AI system involved
- Prosecraft
10 source articles · read the reporting →
Lattice cancels plan to give AI digital workers employee records after backlash
Lattice, an HR software company, announced on July 9th that it would give AI digital workers official employee records. After strong backlash from HR professionals and others on LinkedIn, the company canceled the feature on July 12th, stating it 'will not further pursue digital workers in the product.' The feature was intended to manage AI bots such as Devin and Piper, but the company reversed course.
- Company involved
- Lattice
- AI system involved
- Lattice
6 source articles · read the reporting →