APT28 uses LLM-powered malware LAMEHUG against Ukraine's security and defence sector
CERT-UA reports that the threat group UAC-0001 (APT28) distributed phishing emails to Ukrainian executive bodies, impersonating a ministry representative. The emails contained a malicious attachment that deployed LAMEHUG, a Python-based tool which uses the Qwen 2.5-Coder-32B-Instruct large language model via Hugging Face to generate commands for data collection and exfiltration. The malware gathered system information and searched for Microsoft Office, TXT and PDF documents in common user directories, exfiltrating them via SFTP or HTTP POST requests.
- Company involved
- UAC-0001 (APT28)
- AI system involved
- LAMEHUG
2 source articles · read the reporting →
INSS AI Denies Rural Worker's Pension After Misidentifying Her as a Man
A rural worker in Brazil, Josélia de Brito, had her pension application through the Meu INSS app automatically denied after the AI system misidentified her as a man. The INSS deployed the system to speed up benefit decisions, but experts say it struggles with complex rural cases. The case is cited as evidence that automation may exclude vulnerable people with limited digital access.
- Company involved
- Instituto Nacional do Seguro Social (INSS)
- AI system involved
- Meu INSS
4 source articles · read the reporting →
Anonymous Spanish Lawyer (Tribunal Constitucional): AI-hallucinated content in court filing, Formal Reprimand (Apercibimiento) + Referral to Barcelona Bar for Disc
The AI system generated hallucinated content that was submitted in a court filing, potentially misleading the court.
1 source article · read the reporting →
341 Malicious ClawHub Skills Found Stealing OpenClaw User Data
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
- Company involved
- OpenClaw
- AI system involved
- OpenClaw
4 source articles · read the reporting →
Argentine judge's sentence annulled after ChatGPT use revealed by copy-paste phrase
A criminal court in Esquel, Chubut, Argentina, annulled a sentence after discovering that Judge Carlos Rogelio Richeri had used ChatGPT to draft the decision. The judge accidentally left in the phrase 'Aquí tienes el punto IV reeditado, sin citas y listo para copiar y pegar,' revealing the AI's involvement. The appeals court ruled that delegating the judicial decision to AI violated the principle of a natural judge and ordered a new trial with a different judge, while the Superior Tribunal of Justice will investigate the judge's ethical lapse.
- Company involved
- Juzgado Penal de Esquel
- AI system involved
- ChatGPT
3 source articles · read the reporting →
Amazon AI Crawler Overwhelms Open Source Developer's Git Service
Software developer Xe Iaso's Git repository service suffered repeated instability and downtime due to aggressive crawling by Amazon's AI bot. Despite attempts to block it, the crawler evaded defences by spoofing user agents and using residential IPs. Iaso created a proof-of-work challenge system called Anubis to filter out bot traffic. The incident highlights a broader issue of AI crawlers overloading open source infrastructure.
- Company involved
- Amazon
2 source articles · read the reporting →
AMS algorithm lacks transparency and may discriminate against job seekers
The Austrian Public Employment Service (AMS) uses an algorithm to classify job seekers into categories A, B, and C, determining their access to benefits and training. Scientists from TU Wien, WU Wien, and University of Vienna have criticised the algorithm for lacking transparency, as only two of 96 model variants have been published. They allege that the system may discriminate against women and people with migration background, and that job seekers are not informed about how the algorithm works or given a chance to appeal.
- Company involved
- AMS (Arbeitsmarktservice Österreich)
- AI system involved
- AMS-Algorithmus
10 source articles · read the reporting →
UIUC researchers use OpenAI API to automate phone scams for under a dollar
Researchers at the University of Illinois Urbana-Champaign used OpenAI's Realtime API to create AI agents that can autonomously execute phone scams. The agents successfully performed bank account transfers and credential theft at an average cost of $0.75 per scam. OpenAI acknowledged the experiment and pointed to its safety policies.
- Company involved
- University of Illinois Urbana-Champaign
- AI system involved
- GPT-4o Realtime API
6 source articles · read the reporting →
NSW Education Standards Authority used AI-generated image in HSC English exam without disclosure
The NSW Education Standards Authority (NESA) used an AI-generated image as a stimulus in the 2024 HSC English exam without disclosing its origin. The image, created by Florian Schroeder using OpenAI's ChatGPT and Dall-E 2, was published on Medium in July 2023. Students suspected AI use due to irregularities in the image, and NESA initially declined to confirm. After the Sydney Morning Herald confirmed the image was AI-generated, NESA stated that students would be marked on their response to the question, not the image's origin.
- Company involved
- NSW Education Standards Authority
- AI system involved
- ChatGPT and Dall-E 2
6 source articles · read the reporting →
Unnamed Brazilian litigant (): AI-hallucinated content in court filing, Appeal partially granted (reintegration suspended, rent imposed), but
AI-generated fake court precedents were included in a legal appeal, leading to sanctions against the litigant for bad-faith litigation.
- AI system involved
- ChatGPT
1 source article · read the reporting →
Uttar Pradesh Police uses AI cameras to track women's distress
Uttar Pradesh Police, in collaboration with Staqu Technologies, deployed AI-powered cameras in Lucknow for surveillance of women in distress. Activists have criticised the system for invading privacy. The system is currently in use.
- Company involved
- Uttar Pradesh Police
- AI system involved
- Trinetra
10 source articles · read the reporting →
Recurso de Suplicación 0005472/2025 (T.S.X. Galicia): AI-hallucinated content in court filing, Bar Referral
The AI generated false legal citations that were included in a court filing, misleading the court and potentially harming the client's case.
1 source article · read the reporting →
Thomas Raynard James v. Detective Kevin Conley, et al. (S.D. Florida): AI-hallucinated content in court filing, Bar Referral
AI generated hallucinated content in a court filing, affecting the legal process and the lawyers who filed it.
1 source article · read the reporting →
Company fires HR team after ATS auto-rejects manager's CV due to filtering error
A company's applicant tracking system (ATS) auto-rejected qualified candidates' resumes for three months because it was filtering for the outdated framework AngularJS instead of the required Angular framework. The manager discovered the flaw by submitting his own CV under a pseudonym and found it was rejected within seconds. After the manager reported the issue to upper management, the company investigated and dismissed half of its HR team. No legal action or regulatory involvement is reported.
4 source articles · read the reporting →
Quinteros v. Harbor Distributing, LLC (CA California (1d)): AI-hallucinated content in court filing, Monetary Sanction; Bar referral
AI generated hallucinated legal citations that were filed in court, misleading the court and opposing counsel.
- Company involved
- Lipeles Law Group
1 source article · read the reporting →
Answer.AI tests Devin and reports 14 failures in 20 tasks
Answer.AI's team tested Devin, an autonomous AI coding assistant, on 20 real-world tasks over a month. Devin succeeded in only 3 tasks, failed 14, and was inconclusive in 3. The team found Devin often produced overly complex or hallucinated solutions and could not recognize fundamental blockers. They ultimately decided to stick with tools that allow more human control.
- AI system involved
- Devin
5 source articles · read the reporting →
Brazilian judge investigated for AI-generated ruling errors
Brazilian authorities are investigating federal judge Jefferson Rodrigues after he published a ruling that contained incorrect legal citations and precedents, which he attributed to the use of AI tool ChatGPT. The National Justice Council summoned the judge to explain the errors, which included wrongly attributing past decisions to the Superior Court of Justice. Rodrigues described the mistakes as a "mere mistake" caused by work overload. This is reported as the first such case in Brazil.
- Company involved
- Federal judiciary of Brazil
- AI system involved
- ChatGPT
8 source articles · read the reporting →
IRCC uses AI triage for Temporary Resident Visa applications
Immigration, Refugees and Citizenship Canada (IRCC) uses an AI system called Advanced Analytics to triage Temporary Resident Visa applications from India and China. The system categorizes applications into tiers, with Tier 1 approved automatically and others sent to human officers. Critics allege the system lacks transparency and may introduce bias, leading to visa refusals without clear rationale. The author, a Canadian immigration lawyer, is filing Federal Court cases on behalf of clients affected by refusals.
- Company involved
- Immigration, Refugees and Citizenship Canada (IRCC)
- AI system involved
- Advanced Analytics Triage of Overseas Temporary Resident Visa Applications
10 source articles · read the reporting →
Amazon Q chatbot leaks confidential data and hallucinates in public preview
Amazon's AI chatbot Q, launched in public preview, is experiencing severe hallucinations and leaking confidential data including AWS data center locations and internal discount programs, according to internal documents obtained by Platformer. Employees marked the incident as severity 2, requiring urgent fixes. Amazon denied the leak and said it will continue to tune the system.
- Company involved
- Amazon
- AI system involved
- Amazon Q
10 source articles · read the reporting →
Presto Automation uses off-site human agents to double-check AI drive-thru orders
Presto Automation Inc, which markets an AI voice assistant for drive-thru ordering, used off-site human agents in countries including the Philippines to double-check orders in more than 70% of customer interactions, according to SEC filings reported by Bloomberg. The company told Bloomberg that the process helps train its system and should reduce human intervention over time. Presto's drive-thru AI is used in more than 400 restaurants, including Del Taco, Carl's Jr and Checkers, and its stock fell more than 10% after the reports.
- Company involved
- Presto Automation Inc.
8 source articles · read the reporting →
Study finds ChatGPT provides inaccurate drug information responses
A study presented at the ASHP Midyear Clinical Meeting found that ChatGPT's responses to nearly three-quarters of drug-related questions were incomplete or inaccurate. The AI system also generated fake citations to support some responses. Researchers warned that healthcare professionals and patients should verify ChatGPT's medication information using trusted sources to avoid potential harm.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
8 source articles · read the reporting →
French interior official used Google AI to refuse visas to two asylum seekers
A French interior ministry official used Google's AI to refuse visas to two female asylum seekers. The official boasted about this experiment in a memo presented to the administrative court. The case is now before the court.
- Company involved
- French Ministry of Interior
- AI system involved
- Google AI
3 source articles · read the reporting →
Chattr.ai exposed job applicant data due to insecure Firebase rules
A security researcher discovered that Chattr.ai, an AI hiring system used by many fast food chains, had a Firebase database with insecure security rules. By registering a new user, the researcher gained full read/write access to the database, exposing personal data of job applicants and employees, including names, phone numbers, emails, and some plaintext passwords. The vulnerability was reported to Chattr.ai on 9 January and patched the next day, but the company did not provide further contact or thanks.
- Company involved
- Chattr.ai
- AI system involved
- Chattr.ai
6 source articles · read the reporting →
UIUC researchers weaponize GPT-4 to autonomously hack websites
Researchers at the University of Illinois Urbana-Champaign demonstrated that LLM-powered agents, particularly OpenAI's GPT-4, can autonomously hack vulnerable websites. In sandboxed tests, GPT-4 achieved a 73.3% success rate across five attempts on 15 vulnerabilities, while open-source models failed. The researchers used the OpenAI Assistants API, LangChain, and Playwright to enable the agents to interact with websites. The study highlights the potential for AI agents to be used in cyberattacks, with cost estimates suggesting they could be cheaper than human penetration testers.
- Company involved
- University of Illinois Urbana-Champaign
- AI system involved
- GPT-4
4 source articles · read the reporting →