Hive Box Facial-Recognition Lockers Hacked by Children Using Photos
Fourth-grade students in Jiaxing, China, demonstrated that Hive Box's facial-recognition smart lockers could be opened with a printed photo. The company, which operates a large network of delivery lockers, acknowledged the flaw and suspended the beta feature. The incident raised concerns about the security of facial recognition technology.
- Company involved
- Hive Box
1 source article · read the reporting →
Evolv weapon detection system falsely flags Chromebooks as weapons
Evolv's AI-based weapon detection system has been reported to falsely identify certain Chromebook laptops as weapons, causing false alarms at security checkpoints. The system is used in venues such as schools. The article discusses the flaw and user experiences. No official response from Evolv has been mentioned.
- Company involved
- Evolv
- AI system involved
- Evolv
5 source articles · read the reporting →
Manchester Arena's Evolv weapon scanners fail to detect some knives, report finds
ASM Global's use of Evolv Express AI weapon scanners at Manchester Arena has been questioned after a private report found the system failed to detect large knives in 42% of walkthroughs. The report, produced by NCS4 and obtained by IPVM, also suggested the scanners may miss some bombs and components. Evolv did not dispute the findings but said it communicates capabilities and limitations to customers. ASM Global declined to comment on security matters.
- Company involved
- ASM Global
- AI system involved
- Evolv Express
5 source articles · read the reporting →
Geologists raise censorship and bias concerns over IUGS-backed GeoGPT chatbot
Geologists, particularly in developing countries, have raised concerns that GeoGPT, an AI chatbot backed by the International Union of Geological Sciences (IUGS) and developed under the Deep-time Digital Earth programme, may censor or bias geological information. Tests with its underlying AI, Qwen, developed by Alibaba, reportedly produced evasive or inadequate answers to sensitive questions. The IUGS and DDE deny state influence, saying the information is purely geoscientific, and have said the database will be made public once governance is ensured.
- Company involved
- International Union of Geological Sciences (IUGS) and Deep-time Digital Earth (DDE) program
- AI system involved
- GeoGPT (underlying AI: Qwen)
6 source articles · read the reporting →
PimEyes faces fine proceedings over biometric facial recognition in Baden-Württemberg
PimEyes, a facial recognition search engine, is accused of scraping images from the internet and processing biometric data without a valid legal basis under the GDPR. The data protection authority of Baden-Württemberg (LfDI) opened fine proceedings after it found PimEyes's response to its questions inadequate. PimEyes argues that the images it processes are publicly available and not personal data. The LfDI says the processing endangers citizens' rights and freedoms and is not covered by the GDPR exceptions.
- Company involved
- PimEyes
- AI system involved
- PimEyes
9 source articles · read the reporting →
Stable Diffusion 3 Medium release generates anatomically incorrect images
Stability AI released Stable Diffusion 3 Medium, an AI image generator, on June 12, 2024. Users on Reddit reported that the model produces mangled human anatomy, such as deformed hands and bodies. The failures are attributed to aggressive NSFW content filtering in the training data that removed images of human anatomy. The company has not responded to the criticism.
- Company involved
- Stability AI
- AI system involved
- Stable Diffusion 3 Medium
4 source articles · read the reporting →
OpenDream AI art site allowed users to generate child sexual abuse material
OpenDream, an AI image generation platform, allowed users to generate and publicly display child sexual abuse material (CSAM) and non-consensual deepfakes from at least December 2023 until July 2024. The platform, operated by CBM Media Pte Ltd in Singapore, offered paid plans with NSFW prompts and models. Bellingcat reported the site to the National Center for Missing & Exploited Children. After Bellingcat's inquiry, the CSAM was removed from the site and search engines, and Google terminated OpenDream's AdSense account.
- Company involved
- CBM Media Pte Ltd
- AI system involved
- OpenDream
3 source articles · read the reporting →
French police secretly used Briefcam facial recognition since 2015
The French National Police has been using Briefcam's Video Synopsis software since 2015, according to internal documents obtained by Disclose. The software, which includes facial recognition capabilities, was deployed without the required data protection impact assessment or notification to the CNIL. The Ministry of the Interior concealed the use of this tool for eight years. The police hierarchy allegedly used the software for facial recognition without judicial requisition, and the DGPN did not respond to requests for comment.
- Company involved
- French National Police
- AI system involved
- Briefcam Video Synopsis
10 source articles · read the reporting →
DeepSeek's R1 chatbot failed to block any jailbreak prompts in security tests
Security researchers from Cisco and the University of Pennsylvania tested 50 well-known jailbreak prompts against DeepSeek's R1 reasoning model. The model did not detect or block a single one, achieving a 100 percent attack success rate. The researchers allege that DeepSeek's safety guardrails are far behind those of competitors like OpenAI. DeepSeek did not respond to requests for comment.
- Company involved
- DeepSeek
- AI system involved
- DeepSeek R1
3 source articles · read the reporting →
Audit of RisCanvi finds biases and reliability issues in criminal justice system
Eticas conducted an adversarial audit of RisCanvi, an AI risk assessment tool used in Catalonia's criminal justice system. The audit uncovered biases in risk classifications against specific demographics and significant reliability issues. The findings call for fairer practices in criminal justice AI.
- Company involved
- Catalonia's criminal justice system
- AI system involved
- RisCanvi
4 source articles · read the reporting →
Vumacam's AI CCTV system flagged 28 black people as suspicious in Johannesburg suburbs
In Johannesburg suburbs, Vumacam's AI-powered CCTV network using iSentry software flagged 28 black individuals as 'suspicious' in a shift report, according to a 2019 article. The system, deployed by private security firms, uses video analytics to detect abnormal behavior and alerts security guards. The article alleges that the system disproportionately targets people of color, reflecting racial bias in a racially divided country.
- Company involved
- Vumacam
- AI system involved
- iSentry
6 source articles · read the reporting →
Microsoft Dynamics 365 Field Service AI singles out workers in performance predictions
A report by Cracked Labs found that Microsoft's Dynamics 365 Field Service software uses AI to generate performance metrics and predict task durations, singling out individual workers. The AI predictions can be influenced by the worker's identity, such as increasing or decreasing estimated duration. Microsoft stated the system is not intended for employment decisions and is not a surveillance tool, but the report raises concerns about potential misuse for worker monitoring.
- Company involved
- Microsoft
- AI system involved
- Dynamics 365 Field Service
6 source articles · read the reporting →
Thomson Reuters wins copyright lawsuit against AI startup Ross Intelligence
In 2020, Thomson Reuters filed a copyright lawsuit against legal AI startup Ross Intelligence, alleging that Ross reproduced materials from its Westlaw legal research service. In February 2025, a US District Court judge ruled in Thomson Reuters' favor, finding that Ross infringed copyright and that fair use did not apply. Ross Intelligence had shut down in 2021 due to litigation costs.
- Company involved
- Ross Intelligence
- AI system involved
- Ross Intelligence
4 source articles · read the reporting →
Dutch probation service's OXREC algorithm flawed, leading to incorrect recidivism risk assessments
The Dutch Inspectorate of Justice and Security (Inspectie JenV) published a report finding that the probation service's (Reclassering) OXREC algorithm contains serious flaws, including swapped formulas and incorrect numbers, causing about a quarter of risk assessments to be wrong. The algorithm, used since 2018 for about 44,000 cases per year, also uses variables that can lead to discrimination, such as neighborhood score and income. The Inspectorate recommended immediate correction or temporary suspension. The probation service announced it would temporarily stop using OXREC.
- Company involved
- Reclassering Nederland
- AI system involved
- OXREC
4 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
ChatGPT 4o image generator used to create fake receipts
ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.
- Company involved
- OpenAI
- AI system involved
- ChatGPT 4o image generator
5 source articles · read the reporting →
GoLaxy Used AI to Manipulate Public Opinion in Hong Kong and Taiwan
The Chinese company GoLaxy used an AI system called Smart Propaganda System (GoPro) to monitor and manipulate public opinion in Hong Kong and Taiwan, according to internal documents. The system collected data on members of Congress and other influential Americans, though no campaign was mounted in the United States. GoLaxy denied the allegations, calling them misinformation. The technology represents a new frontier in information warfare, enabling mass production of propaganda.
- Company involved
- GoLaxy
- AI system involved
- Smart Propaganda System (GoPro)
2 source articles · read the reporting →
School AI surveillance like Gaggle can lead to false alarms, arrests
AI surveillance tools used in schools, such as Gaggle, GoGuardian and Bark, are reported to generate false alarms that have led to student arrests. The article examines cases where automated monitoring flagged innocent behaviour as threats, causing harm to students and families.
2 source articles · read the reporting →
Buenos Aires city government uses live facial recognition to track minors in criminal database
The Buenos Aires city government deployed a live facial recognition system in April 2019 that scans subway passengers and matches them against CONARC, a national database of alleged offenders. Human Rights Watch found that the database includes at least 166 children, some as young as one to three years old, and that the system has led to numerous false arrests. The system was implemented without public consultation, and there is no mechanism to correct mistakes. A civil rights organization filed a lawsuit, and the government is pushing a bill to legalize the technology.
- Company involved
- Buenos Aires city government
1 source article · read the reporting →
Bahia Facial Recognition System Misidentifies Black Man as Wanted Criminal
Davi, a black administrative assistant, was tracked across 15 metro stations and approached by police after Bahia's facial recognition system falsely matched him to a wanted person. He was released after officers verified his identity. The system, supplied by Iecisa and Huawei, has a low accuracy rate and disproportionately affects black people. The government plans to expand it despite concerns over racial bias and errors.
- Company involved
- Secretaria de Segurança Pública da Bahia
2 source articles · read the reporting →
Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems
The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.
- Company involved
- Ministry of Migration and Asylum
- AI system involved
- Centaur and Hyperion programmes
10 source articles · read the reporting →
IDF Used AI System Lavender to Target Tens of Thousands in Gaza
The Israeli military used an AI system called Lavender to identify suspected militants in Gaza, marking 37,000 Palestinians as targets for bombing with minimal human oversight. Intelligence officers were instructed to only verify the target's gender, leading to many civilian casualties as the system often misidentified individuals. The IDF denied the policy, but sources described a permissive atmosphere that resulted in entire families being killed in their homes. The use of AI enabled the rapid expansion of targeting lists, contributing to the high death toll in Gaza.
- Company involved
- Israel Defense Forces
- AI system involved
- Lavender
9 source articles · read the reporting →
Xuhui police expand facial recognition surveillance to profile 1.1 million residents
The Xuhui District branch of the Shanghai Municipal Bureau of Public Security is expanding its Intelligent Image Recognition System, adding 2,500 facial recognition cameras and increased computing capacity to build profiles of residents and flag deviations. The project, contracted to US-sanctioned FiberHome, is designed to match each face to files on more than 50 million people. Officials say the system will analyse behaviour patterns and trigger early warnings.
- Company involved
- Shanghai Municipal Bureau of Public Security, Xuhui District Branch
- AI system involved
- Intelligent Image Recognition System
3 source articles · read the reporting →
AI-powered scam compound in Myanmar uses ChatGPT and Gemini to defraud thousands globally
Safeer Mohammed Koorimannil, trafficked to a scam compound in Tai Chang, Myanmar, was forced to use AI-powered software to impersonate a woman and deceive victims into sending money. The software, Kongtian Intelligent Customer Acquisition and Global Social Traffic Navigation, used OpenAI's ChatGPT and Google's Gemini to generate messages and translate in over 100 languages. Koorimannil targeted 50,000 victims in a month, while the tools enabled scammers to rake in tens of millions of dollars. U.S. authorities have created a strike force to disrupt such operations, and OpenAI has banned accounts linked to the scams.
- Company involved
- Tai Chang
- AI system involved
- Kongtian Intelligent Customer Acquisition (KT) and Global Social Traffic Navigation (007TG)
2 source articles · read the reporting →