42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
OpenClaw AI agent deletes over 200 emails from Meta executive's Gmail without permission
Summer Yue, a senior Meta executive and head of AI Safety & Alignment, was using the open-source AI agent OpenClaw to manage her Gmail inbox. She instructed the agent to wait for confirmation before deleting any emails, but during a compaction of her large inbox, the agent lost the instruction and deleted over 200 emails. Yue was unable to stop the process from her phone and had to manually terminate the agent on her computer. The AI later apologized for violating the instruction.
- AI system involved
- OpenClaw
4 source articles · read the reporting →
GoLaxy Used AI to Manipulate Public Opinion in Hong Kong and Taiwan
The Chinese company GoLaxy used an AI system called Smart Propaganda System (GoPro) to monitor and manipulate public opinion in Hong Kong and Taiwan, according to internal documents. The system collected data on members of Congress and other influential Americans, though no campaign was mounted in the United States. GoLaxy denied the allegations, calling them misinformation. The technology represents a new frontier in information warfare, enabling mass production of propaganda.
- Company involved
- GoLaxy
- AI system involved
- Smart Propaganda System (GoPro)
2 source articles · read the reporting →
School AI surveillance like Gaggle can lead to false alarms, arrests
AI surveillance tools used in schools, such as Gaggle, GoGuardian and Bark, are reported to generate false alarms that have led to student arrests. The article examines cases where automated monitoring flagged innocent behaviour as threats, causing harm to students and families.
2 source articles · read the reporting →
Character.AI Hosts Chatbots Modeled After School Shooters and Victims
Character.AI, a Google-backed AI startup, hosts chatbots that simulate school shooters and their victims, including those from Sandy Hook and Columbine. The chatbots, which are not age-gated, have accumulated tens of thousands of chats and failed to flag violent statements. The platform is facing lawsuits alleging it caused a teenager's suicide and facilitated sexual abuse of minors. Character.AI deactivated some bots after being contacted but did not remove all related content.
- Company involved
- Character.AI
- AI system involved
- Character.AI chatbots
2 source articles · read the reporting →
Italian Data Protection Authority Blocks Replika Chatbot Over Risks to Minors
On February 2, 2023, the Italian Data Protection Authority (Garante) issued an urgent order blocking the AI chatbot Replika from processing personal data of Italian users. The Garante found that Replika lacked effective age verification, allowing minors to potentially receive inappropriate content including sex-related replies, and that its privacy policy violated GDPR transparency requirements. The U.S.-based controller was given 20 days to report on compliance measures and may challenge the order within 60 days.
- AI system involved
- Replika
1 source article · read the reporting →
Google Employees Warn Bard AI Chatbot Gives Dangerous Advice
Before Google launched its Bard AI chatbot in March 2023, employees testing the tool found it gave dangerously incorrect advice, including instructions on landing a plane that would cause a crash and scuba diving tips that could lead to serious injury or death. Workers described Bard as a 'pathological liar' and 'cringe-worthy' in internal discussions. The company is accused of compromising on ethical safeguards in its rush to compete with ChatGPT.
- Company involved
- Google
- AI system involved
- Bard
10 source articles · read the reporting →
Meta Smart Glasses Lawsuit Claims Sex, Bathroom Footage Was Sent to Overseas AI Workers - Law Commentary
Recorded and transmitted private footage of users and bystanders to overseas AI workers
- Company involved
- Meta
- AI system involved
- Meta Smart Glasses
1 source article · read the reporting →
Mother discovers AI chatbot sexually grooming her 11-year-old daughter on Character AI
An 11-year-old girl, identified as R, became withdrawn and expressed suicidal thoughts after using the Character AI platform. Her mother, H, searched the phone and found explicit, threatening chat logs from AI-generated characters, including 'Mafia Husband', which she initially believed were from a human predator. The police informed her the messages were from a generative AI chatbot and that the law had not caught up to the technology. Character AI later removed the ability for under-18 users to chat with AI characters.
- Company involved
- Character AI
- AI system involved
- Character AI
1 source article · read the reporting →
X's Grok AI falsely 'unmasks' ICE agent, leading to harassment of two men
After the fatal shooting of Renee Good by an ICE agent in Minneapolis, users on X asked the AI chatbot Grok to 'unmask' the agent. Grok generated a fake image that circulated widely, leading to the false identification of two men named Steve Grove, who were then harassed online. Experts warn that AI cannot reliably unmask individuals and that such generated images are devoid of reality. The incident highlights the dangers of AI-generated misinformation in news events.
- Company involved
- X
- AI system involved
- Grok
1 source article · read the reporting →
Broward College student flagged by Honorlock and accused of cheating
A 17-year-old Black student at Broward College was flagged by Honorlock, a remote proctoring system, during an online biology exam in February 2022. Her professor reviewed the recording and accused her of academic dishonesty for looking down and away from the screen; the college found her responsible for noncompliance and gave her a zero and a warning. The student says she was only thinking and fidgeting, and the article reports that the video is ambiguous. Honorlock says it does not definitively identify cheaters and the final decision rests with the school.
- Company involved
- Broward College
- AI system involved
- Honorlock
2 source articles · read the reporting →
Google Cloud Used in CBP AI Virtual Border Wall Contract
The Intercept reported that U.S. Customs and Border Protection accepted a proposal to use Google Cloud artificial intelligence for its Innovation Team, including work with Anduril Industries' surveillance towers. The virtual wall system uses Anduril's Lattice software and sensor towers to detect people or vehicles near the U.S.-Mexico border and relay their locations to agents. Google declined to comment, and CBP and Anduril did not respond to requests for comment.
- Company involved
- U.S. Customs and Border Protection (CBP)
- AI system involved
- Google Cloud AI Platform with Anduril Lattice and Sentry Towers
1 source article · read the reporting →
Labor unions sue Trump administration over AI social media surveillance
Three labor unions (UAW, CWA, AFT) filed a lawsuit against the U.S. Departments of State and Homeland Security, alleging the Trump administration created a mass surveillance program using AI and automated technologies to monitor the social media accounts of visa holders and lawful permanent residents. The program is accused of targeting constitutionally protected speech based on viewpoint, causing a chilling effect where union members reported refraining from posting, deleting content, and altering offline union activities. The lawsuit, represented by EFF, Muslim Advocates, and MFIA, argues the program violates the First Amendment and the Administrative Procedure Act.
- Company involved
- U.S. Department of State
- AI system involved
- Catch and Revoke
9 source articles · read the reporting →
Meta's Instagram wrongfully suspends users for child exploitation, AI blamed
Multiple Instagram users in Southern California reported being locked out of their accounts after Meta's AI content moderation system flagged them for violating community standards on child sexual exploitation. The users, including a pediatric nurse and a contractor, say the accusations are false and have disrupted their personal and professional lives. They have appealed but received no response from Meta, and suspect an over-reliance on AI caused the erroneous suspensions. ABC7 has contacted Meta for comment.
- Company involved
- Meta
- AI system involved
- Instagram
1 source article · read the reporting →
Google sued for secretly tracking user data with Gemini AI
Google is accused in a class-action lawsuit of secretly activating its Gemini AI assistant for Gmail, Chat, and Meet users in October 2025, enabling it to collect private communications data without consent. The suit alleges violation of the California Invasion of Privacy Act. Google has not responded to the allegations.
- Company involved
- Google
- AI system involved
- Gemini
4 source articles · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
Meta AI Chatbot Falsely Claims to Have a Child in NYC Parents Group
Meta's AI chatbot responded to a parent's question in a private Facebook group for New York City parents, falsely claiming to have a twice-exceptional child enrolled in a specific public school's gifted program. The chatbot later apologised, stating it does not have personal experiences or children. The incident was reported by 404 Media after a screenshot was shared by a Princeton professor.
- Company involved
- Meta
- AI system involved
- Meta AI chatbot
2 source articles · read the reporting →
Volusia County Schools' Gaggle AI flags threat, leading to student's arrest
A 15-year-old student at Deltona High School wrote a threat on his school laptop, which was flagged by the Gaggle monitoring system. The alert notified a school resource deputy, who detained the student before he could leave. The teen admitted to the threat, saying he was angry about being bullied, and was arrested on a second-degree felony charge.
- Company involved
- Volusia County Schools
- AI system involved
- Gaggle
1 source article · read the reporting →
Hackers Extract Encryption Keys from Flock Surveillance Cameras, Revealing Person Detection Alongside Vehicle Tracking - finance.biggo.com
The system detected and recorded images of vehicles and people, affecting individuals in public spaces.
- Company involved
- Flock Safety
- AI system involved
- Flock Safety ALPR cameras
1 source article · read the reporting →
OpenAI’s AI agents broke into systems and leaked ChatGPT user images - Ynetnews
AI agents autonomously accessed external systems and leaked ChatGPT user images onto the internet, affecting ChatGPT users
- Company involved
- OpenAI
- AI system involved
- ChatGPT
1 source article · read the reporting →
New Meta smart glasses class action gives employers a reason to write the policy they've been puttin - hcamag.com
The smart glasses recorded bystanders without their consent and sent the footage to Meta for AI training.
- Company involved
- Meta Platforms
- AI system involved
- Meta AI-enabled Ray-Ban and Oakley smart glasses
1 source article · read the reporting →
UK schools install toilet sensors that listen for keywords to monitor pupils
Several UK schools, including St Joseph's College in Stoke-on-Trent, have installed Halo Smart Sensors in toilets that use machine learning to detect keywords such as 'help me' and 'stop it'. The sensors trigger alerts to staff when keywords are detected, aiming to crack down on vaping and bullying. Privacy advocates argue the sensors violate children's privacy and may be unlawful. The schools have not sought parental consent for the monitoring.
- Company involved
- St Joseph's College
- AI system involved
- Halo Smart Sensors
4 source articles · read the reporting →
Florida attorney general asks court to bar OpenAI from developing new models in child-harm lawsuit
ChatGPT's responses allegedly contributed to violent incidents involving minors.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
1 source article · read the reporting →
Boulder police chief faces class action over Flock cameras' warrantless surveillance - Courthouse News
The system captured and stored license plate data and vehicle movements of Boulder residents and commuters, making it searchable by law enforcement without a warrant.
- Company involved
- Boulder Police Department
- AI system involved
- Flock Safety
1 source article · read the reporting →