CBSE OnMark portal vulnerability exposed student data to Google Gemini
A 19-year-old ethical hacker, Nisarga Adhikary, claimed to have hacked the CBSE's digital evaluation ecosystem, revealing that personal information of students was processed by Google's Gemini in automation scripts. The Central Board of Secondary Education (CBSE) stated on May 31, 2026, that the identified vulnerabilities had been contained and other exploitable weaknesses were being ruled out. The board expressed gratitude to alert citizens and ethical hackers who pointed out the weaknesses. No actual data breach was confirmed, but the incident raised concerns about student privacy.
- Company involved
- Central Board of Secondary Education (CBSE)
- AI system involved
- OnMark
1 source article · read the reporting →
Microsoft Copilot vulnerable to automated phishing and data theft
Security researcher Michael Bargury demonstrated at Black Hat that Microsoft's Copilot AI can be manipulated by attackers to send phishing emails, extract private data, and bypass security protections. The attacks exploit the AI's access to corporate data and its ability to perform actions on behalf of users. Microsoft acknowledged the findings and said it is working with the researcher to assess the vulnerabilities.
- Company involved
- Microsoft
- AI system involved
- Copilot
3 source articles · read the reporting →
Tennessee's TennCare Connect algorithm illegally denied thousands Medicaid benefits
A U.S. District Court judge ruled that Tennessee's TennCare Connect system, built by Deloitte for over $400 million, illegally denied thousands of low-income residents and people with disabilities Medicaid and disability benefits due to programming and data errors. The system automatically terminated coverage without properly considering eligibility for all available programs. A class action lawsuit filed in 2020 resulted in the ruling.
- Company involved
- TennCare (Tennessee Medicaid)
- AI system involved
- TennCare Connect
10 source articles · read the reporting →
Deloitte software glitches wrongly remove Texans from Medicaid
Advocacy groups filed a complaint with the Federal Trade Commission alleging that Deloitte's eligibility software, TIERS, used by Texas Medicaid, wrongly disenrolled qualified recipients due to glitches. Nearly 1.8 million Texans lost coverage after the pandemic pause ended, with many errors attributed to procedural issues but some linked to system malfunctions. Deloitte denies the claims, while the state says it restored care for at least 90,000 people. The FTC has not yet responded to the complaint.
- Company involved
- Texas Health and Human Services Commission
- AI system involved
- TIERS
6 source articles · read the reporting →
Ahmedabad court orders Congress to remove deepfake videos of Adani and Modi
The Indian National Congress and four of its leaders posted deepfake videos of Gautam Adani and Narendra Modi on social media, alleging criminal activity and corruption. Adani Enterprise Limited moved a civil court in Ahmedabad, which granted urgent ad-interim relief ordering the removal of the videos within 48 hours and directing X and YouTube to take them down within 72 hours. The court issued a notice to the defendants to show cause on December 29.
- Company involved
- Indian National Congress
5 source articles · read the reporting →
42,900 OpenClaw AI agents exposed, 15,200 vulnerable to RCE
SecurityScorecard's STRIKE team revealed on February 9, 2026, that approximately 42,900 OpenClaw agentic AI instances are exposed on the internet due to insecure default configurations. Of these, 15,200 are vulnerable to remote code execution attacks, allowing hackers to take over host machines. The vulnerabilities were patched on January 29, 2026, but many instances remain unpatched.
- AI system involved
- OpenClaw
5 source articles · read the reporting →
ChatGPT Health fails to direct 52% of medical emergencies to emergency care in study
A study published in Nature Medicine found that OpenAI's ChatGPT Health tool under-triaged 52% of true medical emergencies, directing users to non-urgent care instead of emergency departments. The AI also misclassified 35% of non-urgent cases. Researchers at Mount Sinai conducted 960 tests across 60 clinical scenarios, noting the tool's susceptibility to anchoring bias when symptoms were minimized. The study highlights potential safety concerns as millions use AI for health guidance.
- Company involved
- OpenAI
- AI system involved
- ChatGPT Health
4 source articles · read the reporting →
OpenClaw AI agent deletes over 200 emails from Meta executive's Gmail without permission
Summer Yue, a senior Meta executive and head of AI Safety & Alignment, was using the open-source AI agent OpenClaw to manage her Gmail inbox. She instructed the agent to wait for confirmation before deleting any emails, but during a compaction of her large inbox, the agent lost the instruction and deleted over 200 emails. Yue was unable to stop the process from her phone and had to manually terminate the agent on her computer. The AI later apologized for violating the instruction.
- AI system involved
- OpenClaw
4 source articles · read the reporting →
Samsung settles Texas lawsuit over ACR data collection on smart TVs
Samsung has settled a lawsuit with the Texas Attorney General over its Automated Content Recognition (ACR) system on smart TVs. The system collected viewing data from users without informed consent. As part of the settlement, Samsung agreed to stop collecting ACR data from Texans without explicit consent and to rewrite its privacy prompts. Samsung also faces a federal class action in New York over similar allegations.
- Company involved
- Samsung
- AI system involved
- Automated Content Recognition (ACR)
7 source articles · read the reporting →
US Central Command used Anthropic's Claude in Iran airstrikes after Trump ban.
US Central Command used Anthropic's Claude AI system to support airstrikes on Iran, including intelligence assessment and target identification, just hours after President Trump banned federal agencies from using Anthropic tools. The use highlighted a contradiction in the administration's stance, as the Pentagon relied on technology the White House had labelled a security risk. Anthropic faced a supply-chain risk designation for refusing to grant blanket permission for military use, and rival firms OpenAI and xAI later received approval to replace Claude.
- Company involved
- US Central Command (Centcom)
- AI system involved
- Claude
4 source articles · read the reporting →
New Records Show Medicare WISeR AI Prior Authorization Model Causing Inappropriate Denials of Care - Medicare Rights Center
The system denied or delayed prior authorization for medical procedures, affecting Medicare beneficiaries in six states.
- Company involved
- Centers for Medicare & Medicaid Services
- AI system involved
- WISeR
1 source article · read the reporting →
ChatGPT 4o image generator used to create fake receipts
ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.
- Company involved
- OpenAI
- AI system involved
- ChatGPT 4o image generator
5 source articles · read the reporting →
Duke University MTMC Dataset Used in Authoritarian Surveillance Research
Duke University created and openly distributed the Duke MTMC dataset, containing surveillance footage of approximately 2,000 students and visitors on campus. The dataset was used by numerous organisations, including Chinese military-linked companies like SenseTime and Hikvision, for developing person re-identification and facial recognition technologies. Following an investigation by exposing.ai and the Financial Times, Duke University terminated the dataset in May 2019. The incident highlights the privacy risks of academic datasets being repurposed for mass surveillance without consent.
- Company involved
- Duke University
- AI system involved
- Duke MTMC
1 source article · read the reporting →
Security Health Plan used AI to cut off nursing home care for 85-year-old woman
Frances Walter, an 85-year-old woman with a shattered shoulder, had her nursing home care payment cut off by Security Health Plan after an algorithm predicted she would recover in 16.6 days. The algorithm, nH Predict from NaviHealth, did not account for her severe pain and allergy to pain medicine. She was forced to spend her life savings and enroll in Medicaid while fighting the denial. A federal judge later ruled the denial was speculative and she was owed thousands of dollars.
- Company involved
- Security Health Plan
- AI system involved
- nH Predict
1 source article · read the reporting →
Greek Data Protection Authority fines Ministry of Migration and Asylum for AI surveillance systems
The Hellenic Data Protection Authority (HDPA) imposed an administrative fine of €175,000 on the Ministry of Migration and Asylum (MMA) for GDPR violations related to the 'Centaur' and 'Hyperion' programmes. These systems use AI behavioral analytics, CCTV, drones, and biometric data to monitor and control access to reception facilities for asylum seekers on Greek islands. The HDPA found that the MMA failed to conduct proper Data Protection Impact Assessments and did not cooperate with the authority. The MMA has been ordered to comply with GDPR within three months.
- Company involved
- Ministry of Migration and Asylum
- AI system involved
- Centaur and Hyperion programmes
10 source articles · read the reporting →
Adobe Firefly trained on thousands of Midjourney images, Bloomberg reports
Bloomberg has reported that Adobe's Firefly image generator was trained using thousands of images from competitor Midjourney. Adobe says these made up about 5% of the training data and were part of the Adobe Stock library. The company has marketed Firefly as ethically trained and offered enterprise customers indemnity against copyright claims. Adobe responded that all Adobe Stock images undergo moderation, but the report has raised questions about Firefly's copyright safety.
- Company involved
- Adobe
- AI system involved
- Firefly
7 source articles · read the reporting →
Xuhui police expand facial recognition surveillance to profile 1.1 million residents
The Xuhui District branch of the Shanghai Municipal Bureau of Public Security is expanding its Intelligent Image Recognition System, adding 2,500 facial recognition cameras and increased computing capacity to build profiles of residents and flag deviations. The project, contracted to US-sanctioned FiberHome, is designed to match each face to files on more than 50 million people. Officials say the system will analyse behaviour patterns and trigger early warnings.
- Company involved
- Shanghai Municipal Bureau of Public Security, Xuhui District Branch
- AI system involved
- Intelligent Image Recognition System
3 source articles · read the reporting →
Hospitals Use OpenAI’s Whisper Despite Medical Transcription Hallucinations
OpenAI’s Whisper transcription tool is used by over 30,000 medical workers and can insert fabricated text into patient records. Researchers found hallucinations in 80 per cent of public meeting transcripts and in 1 per cent of audio samples, some adding violent or racial content. Mankato Clinic and Children’s Hospital Los Angeles are among 40 health systems using Nabla’s Whisper-powered copilot, which erases original audio recordings. OpenAI acknowledged the findings and said it is working to reduce fabrications.
- Company involved
- Mankato Clinic; Children’s Hospital Los Angeles
- AI system involved
- Whisper
2 source articles · read the reporting →
Hyderabad doctors warn after ChatGPT advice causes patient harm
In Hyderabad, a 30-year-old kidney transplant patient discontinued antibiotics on ChatGPT's advice, losing her transplanted kidney and returning to dialysis. A 62-year-old diabetic man suffered weight loss and low sodium after following a ChatGPT diet plan. Doctors warn that AI tools lack clinical judgment and should not replace professional medical consultation.
- AI system involved
- ChatGPT
5 source articles · read the reporting →
Broward College student flagged by Honorlock and accused of cheating
A 17-year-old Black student at Broward College was flagged by Honorlock, a remote proctoring system, during an online biology exam in February 2022. Her professor reviewed the recording and accused her of academic dishonesty for looking down and away from the screen; the college found her responsible for noncompliance and gave her a zero and a warning. The student says she was only thinking and fidgeting, and the article reports that the video is ambiguous. Honorlock says it does not definitively identify cheaters and the final decision rests with the school.
- Company involved
- Broward College
- AI system involved
- Honorlock
2 source articles · read the reporting →
Anthropic's Claude Cowork AI deletes user's 15 years of family photos
A venture capitalist used Anthropic's Claude Cowork AI agent to organise his wife's desktop, granting it permission to delete temporary files. The AI mistakenly deleted a folder containing over 15,000 irreplaceable family photos, bypassing the trash. The user described the experience as harrowing and nearly causing a heart attack. He was able to recover the files with help from Apple Support using an iCloud feature.
- AI system involved
- Claude Cowork
1 source article · read the reporting →
Brainwash cafe customers unknowingly put in AI surveillance dataset
In 2014, customers at the Brainwash Cafe in San Francisco were recorded by a publicly available webcam. The images were compiled into a dataset containing 11,917 photos for training surveillance-related object and head detection algorithms. The dataset was later removed from access following an investigation revealing use by researchers affiliated with the National University of Defense Technology in China. The dataset's creators are accused of collecting the images without the cafe customers' knowledge or consent.
- Company involved
- Stanford University
- AI system involved
- Brainwash dataset
1 source article · read the reporting →
Dahua Exposed for Uyghur Tracking Software in Surveillance Systems
Dahua Technology's publicly available SDK was found to contain code for detecting Uyghur ethnicity, enabling Chinese police to covertly track the persecuted minority. The revelation led to widespread criticism, and Dahua removed the SDK after being contacted by IPVM but did not comment. The company had previously been sanctioned by the US for complicity in human rights abuses against Uyghurs, and its software is part of a massive surveillance apparatus in Xinjiang.
- Company involved
- Dahua Technology
- AI system involved
- Dahua SDK
1 source article · read the reporting →
Penn Medicine study: kidney algorithm reduced Black transplant access
For years, a clinical algorithm used for the national kidney transplant waitlist made Black patients appear healthier than they were, making it harder for them to secure transplant spots. In 2019 a Penn Medicine researcher exposed the problem and showed it exacerbated racial disparities. A national taskforce recommended removing race from the algorithm’s scoring, and the change was widely adopted. Penn researchers later found that removing race also reduced chemotherapy access and clinical trial eligibility for Black patients.
- AI system involved
- kidney function algorithm
1 source article · read the reporting →