CBSE OnMark portal vulnerability exposed student data to Google Gemini
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
- Company involved
- Central Board of Secondary Education (CBSE)
- AI system involved
- OnMark
1 source article · read the reporting →
Mass AI cheating scandal at Yonsei University with hundreds of students using ChatGPT
A large-scale cheating scandal has erupted at Yonsei University, where hundreds of students in a third-year online course are suspected of using AI tools such as ChatGPT to cheat on their midterm exam. The professor discovered signs of misconduct and offered students a chance to confess, with those coming forward receiving a zero but no further penalty. A poll on a student community app indicated that over half of respondents admitted to cheating. The university has not yet established clear guidelines on AI use.
- Company involved
- Yonsei University
- AI system involved
- ChatGPT
6 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
School AI surveillance like Gaggle can lead to false alarms, arrests
AI surveillance tools used in schools, such as Gaggle, GoGuardian and Bark, are reported to generate false alarms that have led to student arrests. The article examines cases where automated monitoring flagged innocent behaviour as threats, causing harm to students and families.
2 source articles · read the reporting →
Duke University MTMC Dataset Used in Authoritarian Surveillance Research
Duke University created and openly distributed the Duke MTMC dataset, containing surveillance footage of approximately 2,000 students and visitors on campus. The dataset was used by numerous organisations, including Chinese military-linked companies like SenseTime and Hikvision, for developing person re-identification and facial recognition technologies. Following an investigation by exposing.ai and the Financial Times, Duke University terminated the dataset in May 2019. The incident highlights the privacy risks of academic datasets being repurposed for mass surveillance without consent.
- Company involved
- Duke University
- AI system involved
- Duke MTMC
1 source article · read the reporting →
Broward College student flagged by Honorlock and accused of cheating
A 17-year-old Black student at Broward College was flagged by Honorlock, a remote proctoring system, during an online biology exam in February 2022. Her professor reviewed the recording and accused her of academic dishonesty for looking down and away from the screen; the college found her responsible for noncompliance and gave her a zero and a warning. The student says she was only thinking and fidgeting, and the article reports that the video is ambiguous. Honorlock says it does not definitively identify cheaters and the final decision rests with the school.
- Company involved
- Broward College
- AI system involved
- Honorlock
2 source articles · read the reporting →
Meta fails to block hate speech ads in Kenya test
Global Witness and Foxglove submitted test ads containing violent hate speech in English and Swahili to Facebook. The ads were approved for publication, demonstrating that Meta's content moderation systems failed to detect the hate speech. The groups had previously conducted similar tests in Myanmar and Ethiopia with the same result. Meta did not respond to the groups' outreach.
- Company involved
- Meta
- AI system involved
- Facebook's content moderation system
2 source articles · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
Meta AI Chatbot Falsely Claims to Have a Child in NYC Parents Group
Meta's AI chatbot responded to a parent's question in a private Facebook group for New York City parents, falsely claiming to have a twice-exceptional child enrolled in a specific public school's gifted program. The chatbot later apologised, stating it does not have personal experiences or children. The incident was reported by 404 Media after a screenshot was shared by a Princeton professor.
- Company involved
- Meta
- AI system involved
- Meta AI chatbot
2 source articles · read the reporting →
FTC Orders Edmodo to Stop Unlawful Collection of Children's Data for Advertising
The FTC filed a complaint against Edmodo, an education technology provider, alleging that it collected personal information from children under 13 without parental consent and used it for advertising, in violation of the COPPA Rule. Edmodo also allegedly outsourced its compliance responsibilities to schools, providing them with inadequate information. Under a proposed order, Edmodo will be required to delete improperly collected data and change its practices, and faces a suspended $6 million penalty.
- Company involved
- Edmodo, LLC
- AI system involved
- Edmodo
1 source article · read the reporting →
US Maven targeting system kills 175 at Iranian school after database error
On 28 February 2026, US forces struck the Shajareh Tayyebeh primary school in Minab, Iran, killing between 175 and 180 people, most of them girls. The targeting was carried out by the Maven Smart System, built by Palantir, which had classified the building as a military facility based on an outdated Defense Intelligence Agency database. Although media attention focused on the chatbot Claude, the real failure was a bureaucratic one: the database had not been updated to reflect the building's conversion into a school years earlier. The incident highlights the lethal consequences of compressed kill chains and automated targeting infrastructure.
- Company involved
- US Department of Defense
- AI system involved
- Maven Smart System
2 source articles · read the reporting →
Privacy group files complaint against proctoring companies over AI surveillance
The Electronic Privacy Information Center (EPIC) filed a complaint with the District of Columbia attorney general against five exam proctoring companies—Respondus, ProctorU, Proctorio, Examity, and Honorlock—alleging unfair and deceptive business practices. The companies are accused of using opaque AI algorithms to flag cheating and collecting excessive biometric data from students. Students have reported that the facial recognition software fails to detect dark skin tones, preventing them from taking exams. EPIC has also sent demand letters threatening civil suits if the companies do not stop their practices.
- Company involved
- Proctorio, Respondus, ProctorU, Examity, Honorlock
10 source articles · read the reporting →
Minneapolis schools use Gaggle AI to monitor students' online activity
Minneapolis Public Schools deployed Gaggle, an AI-powered surveillance system, to monitor students' school-issued Google and Microsoft accounts during remote learning. The system flagged thousands of incidents, including references to self-harm and pornography, raising privacy concerns. Critics argue the surveillance undermines student trust and may deter them from seeking help. The district defended the tool as a way to identify students in distress.
- Company involved
- Minneapolis Public Schools
- AI system involved
- Gaggle
9 source articles · read the reporting →
Alpha School parents allege harm from AI-driven learning software
Parents of students at Alpha School in Brownsville, Texas, allege that the school's AI-driven learning software caused their children psychological distress and physical harm. One 9-year-old girl was forced to repeat multiplication lessons hundreds of times, leading to crying episodes and weight loss, and was denied snacks until she met software metrics. The school denies the allegations and says it prioritises a safe environment.
- Company involved
- Alpha School
- AI system involved
- IXL
5 source articles · read the reporting →