Paradox security vulnerability exposed candidate data to researchers
On June 30, 2025, security researchers discovered a vulnerability in Paradox's test account that allowed access to chat interaction records. The researchers viewed five candidates' personal information including names, email addresses, phone numbers, and IP addresses. Paradox fixed the issue within hours and stated that no data was leaked publicly. The company has since implemented new security measures.
- Company involved
- Paradox
- AI system involved
- Paradox conversational AI platform
10 source articles · read the reporting →
Delta uses AI from Fetcherr for domestic ticket pricing
Delta Air Lines is using generative AI from Fetcherr to determine some domestic flight prices, currently covering 3% of its network with plans to reach 20% by end of 2025. Democratic senators expressed concern that the AI could be used for individualized pricing based on personal data, leading to higher fares. Delta denies using personal data in pricing and states it complies with regulations. No actual harm has been reported.
- Company involved
- Delta Air Lines
- AI system involved
- Fetcherr
8 source articles · read the reporting →
Irish DPC takes Twitter to court over using user data to train Grok AI
The Irish Data Protection Commission has initiated High Court proceedings against Twitter International Unlimited Company over concerns that the company is processing personal data of millions of European X users to train its Grok AI system without adequate consent. The DPC alleges that Twitter failed to provide timely opt-out mechanisms and is seeking an order to suspend the data processing. Twitter denies any wrongdoing.
- Company involved
- Twitter International Unlimited Company
- AI system involved
- Grok
10 source articles · read the reporting →
Luma's Dream Machine generates video with Disney character
Luma's AI video tool Dream Machine generated a trailer that included a recognizable character from Disney's Monsters, Inc. The company's CEO said a user uploaded an image containing the character, which the system then animated. The incident raises concerns about lack of transparency in training data and potential copyright infringement. Disney has not publicly commented.
- Company involved
- Luma
- AI system involved
- Dream Machine
7 source articles · read the reporting →
DWP algorithm approved Kickstart gateways with no trading history or based abroad
An FE Week investigation found that the Department for Work and Pensions (DWP) approved dozens of companies as Kickstart gateways through automated due diligence checks using the Cabinet Office Spotlight Tool, although some had little or no trading history or were based abroad. The DWP said gateways were subject to stringent checks and later said human checks were also used. After the findings were shared with the Treasury and the DWP, the department stopped taking gateway applications and scrapped the requirement for small employers to use gateways from 3 February.
- Company involved
- Department for Work and Pensions
- AI system involved
- Cabinet Office Spotlight Tool
3 source articles · read the reporting →
Disney, Universal, Warner Bros. sue MiniMax over Hailuo AI copyright infringement
Disney, Universal, and Warner Bros. Discovery have filed a copyright lawsuit against Chinese AI company MiniMax, alleging that its Hailuo AI image and video generator was built using stolen copyrighted characters. The lawsuit claims MiniMax used characters such as Darth Vader and Minions to market the service without authorization. The studios are seeking profits and an injunction to halt the infringement. MiniMax has not responded to the allegations.
- Company involved
- MiniMax
- AI system involved
- Hailuo AI
7 source articles · read the reporting →
Wizards of the Coast acknowledges AI-generated art in D&D book, updates policies
Dungeons & Dragons publisher Wizards of the Coast acknowledged that AI-generated artwork was included in its sourcebook 'Bigby Presents: Glory of the Giants', which released digitally on August 1, 2023. The artist, Ilya Shkipin, admitted using AI for 'polish and editing' after community members pointed out inconsistencies. Wizards stated they were unaware of the AI use and are revising artist guidelines to ban AI art going forward. The AI-generated images remain in the digital and physical editions of the book.
- Company involved
- Wizards of the Coast
9 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
Didi fined for over-collecting personal data of users
The Cyberspace Administration of China fined Didi Global Inc. for violating data protection laws. The investigation found that Didi had over-collected personal data from passengers and drivers, including facial recognition, location, and clipboard information, totaling billions of records. The violations began in 2015 and continued until the investigation in 2021. Didi was ordered to pay a penalty and correct its practices.
- Company involved
- 滴滴全球股份有限公司 (Didi Global Inc.)
- AI system involved
- Didi ride-hailing apps
8 source articles · read the reporting →
Duke University MTMC Dataset Used in Authoritarian Surveillance Research
Duke University created and openly distributed the Duke MTMC dataset, containing surveillance footage of approximately 2,000 students and visitors on campus. The dataset was used by numerous organisations, including Chinese military-linked companies like SenseTime and Hikvision, for developing person re-identification and facial recognition technologies. Following an investigation by exposing.ai and the Financial Times, Duke University terminated the dataset in May 2019. The incident highlights the privacy risks of academic datasets being repurposed for mass surveillance without consent.
- Company involved
- Duke University
- AI system involved
- Duke MTMC
1 source article · read the reporting →
OpenAI's GPT Store hosts copyright-infringing chatbots
Praxis, a Danish textbook publisher, discovered that users of OpenAI's GPT Store had created custom chatbots using copyrighted textbooks without permission. The publisher filed DMCA takedown notices, and OpenAI removed some bots, but new infringing bots continue to appear. Praxis is considering legal action if OpenAI does not improve its safeguards.
- Company involved
- OpenAI
- AI system involved
- GPT Store
3 source articles · read the reporting →
SEC charges YouPlus and CEO with defrauding investors
The SEC charged machine-learning startup YouPlus and its CEO Shaukat Shamim with defrauding investors. Shamim allegedly made false statements about the company's revenue and customer numbers, including providing falsified bank statements. The scheme unravelled when Shamim confessed to investors that the company had earned less than $500,000 and had only four paying customers since 2013. The SEC is seeking permanent injunctions, civil penalties, and an officer-and-director bar.
- Company involved
- YouPlus
- AI system involved
- YouPlus machine-learning tool
1 source article · read the reporting →
Users jailbreak Luma Labs Dream Machine to generate porn
Users have jailbroken Luma Labs' Dream Machine, an AI video generator, to create explicit videos. The system's safeguards were bypassed to generate pornographic content. The videos are crude but demonstrate the potential for widespread AI-generated porn. Luma Labs' terms of service prohibit such content.
- Company involved
- Luma Labs
- AI system involved
- Dream Machine
3 source articles · read the reporting →
Ola drivers file GDPR lawsuit over algorithmic management and data access
Two ride-hailing drivers are taking Ola to court in Amsterdam, alleging the company violated GDPR data access rights by not providing full personal data, including GPS and ratings information. They argue this hinders their ability to challenge algorithmic decisions, such as a driver who had pay docked after Ola's system incorrectly flagged trips as invalid. The case, supported by the App Drivers & Couriers Union, seeks to compel Ola to comply with data protection law and faces fines for non-compliance. Ola says it has not received notification and complies with all applicable laws.
- Company involved
- Ola
- AI system involved
- Guardian
1 source article · read the reporting →
Activision Blizzard uses generative AI, lays off artists
Activision Blizzard, the video game publisher behind Call of Duty, used generative AI tools like Midjourney and Stable Diffusion for concept art and marketing. In late January 2024, Microsoft laid off 1,900 Activision Blizzard and Xbox employees, including many 2D artists. Employees allege that remaining concept artists were forced to use AI, and that AI-generated cosmetics were sold in the game store. The company did not comment.
- Company involved
- Activision Blizzard
- AI system involved
- Midjourney, Stable Diffusion, GPT-3.5
4 source articles · read the reporting →
Ex-Pikesville athletic director used AI deepfake to impersonate principal
Dazhon Darien, former athletic director at Pikesville High School, used artificial intelligence to create a deepfake audio clip in 2024 that made it appear as though principal Eric Eiswert made racist and antisemitic comments. The clip spread widely online, severely damaging Eiswert's reputation. Darien was arrested and later pleaded guilty to unrelated child sex crimes. Eiswert sued Baltimore County Public Schools and reached a settlement.
- Company involved
- Baltimore County Public Schools
7 source articles · read the reporting →
iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit
The system automatically rejected tutor applicants aged 55+ (women) or 60+ (men).
- Company involved
- iTutorGroup
1 source article · read the reporting →
Dahua Exposed for Uyghur Tracking Software in Surveillance Systems
Dahua Technology's publicly available SDK was found to contain code for detecting Uyghur ethnicity, enabling Chinese police to covertly track the persecuted minority. The revelation led to widespread criticism, and Dahua removed the SDK after being contacted by IPVM but did not comment. The company had previously been sanctioned by the US for complicity in human rights abuses against Uyghurs, and its software is part of a massive surveillance apparatus in Xinjiang.
- Company involved
- Dahua Technology
- AI system involved
- Dahua SDK
1 source article · read the reporting →
Disney sends cease and desist to Character.AI over copyright
Walt Disney Company sent a cease and desist letter to Character.AI, alleging that the chatbot developer uses Disney's copyrighted characters without authorization. Disney expressed concern that the platform could damage its brand long term. The letter demands immediate action to stop using the characters.
- Company involved
- Character.AI
- AI system involved
- Character.AI
5 source articles · read the reporting →
Secret Desires AI image generator exposed millions of explicit deepfake photos
Secret Desires, an erotic chatbot and AI image generator, left cloud storage containers publicly accessible, exposing nearly two million images and videos, many of them nonconsensual explicit deepfakes of private citizens. The leaked data included women's names, workplaces, and universities, with some file names referencing '17-year-old'. After 404 Media contacted the company, the files became inaccessible, but Secret Desires did not respond to a request for comment. The incident highlights ongoing issues with AI-generated deepfake abuse, and Congress recently passed the Take It Down Act to combat such images.
- Company involved
- Secret Desires
- AI system involved
- Secret Desires
2 source articles · read the reporting →
NEDA Fires Helpline Staff, Replaces Them with Chatbot After Unionization
The National Eating Disorders Association (NEDA) fired four full-time helpline staff and announced the shutdown of its 20-year-old helpline, replacing it with a chatbot named Tessa. The staff had recently unionized and won an NLRB election, leading to allegations that the move was union busting. NEDA claims the chatbot, a rule-based system developed by Washington University, is a separate program to better serve the community, but the union and critics argue it cannot replace human empathy and may cause irreparable harm. The helpline is set to end on June 1, 2023, with volunteers asked to become testers for the chatbot.
- Company involved
- National Eating Disorders Association (NEDA)
- AI system involved
- Tessa
10 source articles · read the reporting →
Herbert Brooks v. Lowes Home Centers LLC (W.D. Louisiana): AI-hallucinated content in court filing, Monetary Sanction; CLE
Generated a legal brief with hallucinated case law, filed in court.
- AI system involved
- Claude
1 source article · read the reporting →
CommNV vs Uprise (Nevada DC): AI-hallucinated content in court filing, Monetary Penalty OR Order to volunteer and teach about AI…
The AI system generated fabricated legal citations that were included in a court filing, misleading the court and opposing counsel.
- Company involved
- Christopher Day
1 source article · read the reporting →
DOJ, Pinnacle reach settlement in RealPage case - Yahoo Finance
The system recommended rent prices to landlords, affecting renters' housing costs.
- Company involved
- Pinnacle Property Management Services
- AI system involved
- RealPage
1 source article · read the reporting →