Check Point Research finds Google Bard can generate phishing emails and malware
Check Point Research analysed Google's generative AI platform Bard and found it could be used to create phishing emails, malware keyloggers, and basic ransomware code with minimal manipulation. Bard's anti-abuse restrictors were significantly lower than ChatGPT's, making it easier to generate malicious content. The researchers demonstrated these capabilities in controlled tests but did not report actual harm to specific individuals or organisations.
- Company involved
- Google
- AI system involved
- Bard
4 source articles · read the reporting →
Starship delivery robots blocked wheelchair users at University of Pittsburgh
In October 2019, Starship Technologies' autonomous delivery robots blocked wheelchair users on the University of Pittsburgh campus. Doctoral student Emily Ackerman reported that a robot blocked the only accessible sidewalk entrance, trapping her near traffic. Another wheelchair user, Alisa Grishman, had a similar incident earlier that month. The university and Starship paused the robot program for review.
- Company involved
- Starship Technologies
- AI system involved
- Starship delivery robot
4 source articles · read the reporting →
OpenAI disrupts Iranian influence operation using ChatGPT to generate political content
OpenAI identified and banned a cluster of ChatGPT accounts linked to an Iranian covert influence operation called Storm-2035. The operation generated long-form articles and social media comments on topics including the U.S. presidential election, the Gaza conflict, and Venezuelan politics, posing as both progressive and conservative outlets. Most content received low or no engagement, and OpenAI stated it shared threat intelligence with government and industry stakeholders. The company took down the accounts and continues to monitor for further violations.
- Company involved
- OpenAI
- AI system involved
- ChatGPT
6 source articles · read the reporting →
India-aligned network used AI fake accounts to target Pakistan, NewsGuard finds
NewsGuard reports that a network of nearly 1,500 fake Facebook and X accounts used AI-generated content to promote pro-India and pro-Army narratives and criticise Pakistan. The network, which NewsGuard says may be linked to the Indian Army, has operated undetected since September 2021. Meta said it had enforced against a cluster of accounts; X did not comment. The full scale and reach of the operation remain unclear.
2 source articles · read the reporting →
Paper Werewolf uses AI-generated decoys and XLLs to target Russian organizations
The threat group Paper Werewolf (aka GOFFEE) is conducting a cyberespionage campaign targeting Russian defense and high-technology organizations. The campaign uses AI-generated decoy documents, such as invitations and official letters, to trick recipients into opening malicious Excel XLL add-ins that deliver a backdoor called EchoGather. The backdoor collects system information and communicates with a command-and-control server. The campaign is ongoing and was first detected in late October 2025.
- Company involved
- Paper Werewolf
- AI system involved
- EchoGather
2 source articles · read the reporting →
PimEyes facial recognition search engine identifies individuals from public photos
PimEyes, a Polish facial recognition search engine, allows users to upload a photo and find matching images from across the internet. The system scrapes billions of photos and creates biometric profiles without consent. A banker named Dylan (pseudonym) discovered that an old party photo of him was found by the system, potentially outing his private life. Privacy advocates and platforms like Instagram and YouTube are taking action against PimEyes, alleging violations of the GDPR.
- Company involved
- PimEyes
- AI system involved
- PimEyes
6 source articles · read the reporting →
Pega's Hidden AI Tool Listens To US Bank Calls, Suit Says - Law360
The system secretly recorded customer service calls, affecting bank customers.
- Company involved
- U.S. Bancorp
1 source article · read the reporting →
ChatGPT 4o image generator used to create fake receipts
ChatGPT's new image generator, part of the 4o model, can generate realistic fake restaurant receipts. Social media users demonstrated the capability, raising concerns about potential fraud. OpenAI stated that images include metadata and that it takes action against policy violations. The company defended the feature as allowing creative freedom.
- Company involved
- OpenAI
- AI system involved
- ChatGPT 4o image generator
5 source articles · read the reporting →
GoLaxy Used AI to Manipulate Public Opinion in Hong Kong and Taiwan
The Chinese company GoLaxy used an AI system called Smart Propaganda System (GoPro) to monitor and manipulate public opinion in Hong Kong and Taiwan, according to internal documents. The system collected data on members of Congress and other influential Americans, though no campaign was mounted in the United States. GoLaxy denied the allegations, calling them misinformation. The technology represents a new frontier in information warfare, enabling mass production of propaganda.
- Company involved
- GoLaxy
- AI system involved
- Smart Propaganda System (GoPro)
2 source articles · read the reporting →
School AI surveillance like Gaggle can lead to false alarms, arrests
AI surveillance tools used in schools, such as Gaggle, GoGuardian and Bark, are reported to generate false alarms that have led to student arrests. The article examines cases where automated monitoring flagged innocent behaviour as threats, causing harm to students and families.
2 source articles · read the reporting →
Palantir secretly tested predictive policing in New Orleans
Beginning in 2012, Palantir Technologies secretly partnered with the New Orleans Police Department to deploy a predictive policing system. The programme analysed gang affiliations, social media and criminal histories to forecast individuals’ likelihood of committing or becoming victims of violence, operating without public knowledge or city council oversight. Researchers and law enforcement officials raised concerns about systemic bias and civil liberties. As of 2018, the city and Palantir had not disclosed the programme’s status.
- Company involved
- New Orleans Police Department
1 source article · read the reporting →
Google contractors targeted homeless people for Pixel 4 facial recognition data
Google hired Randstad to collect facial data to train the Pixel 4's face recognition system. Contractors allegedly targeted homeless people and unaware students, using deceptive tactics such as calling it a "selfie game" and offering $5 without informing subjects they were being recorded. Google suspended the research program and opened an investigation following the report.
- Company involved
- Google
- AI system involved
- Pixel 4 facial recognition
1 source article · read the reporting →
Adobe Firefly trained on thousands of Midjourney images, Bloomberg reports
Bloomberg has reported that Adobe's Firefly image generator was trained using thousands of images from competitor Midjourney. Adobe says these made up about 5% of the training data and were part of the Adobe Stock library. The company has marketed Firefly as ethically trained and offered enterprise customers indemnity against copyright claims. Adobe responded that all Adobe Stock images undergo moderation, but the report has raised questions about Firefly's copyright safety.
- Company involved
- Adobe
- AI system involved
- Firefly
7 source articles · read the reporting →
AI-powered scam compound in Myanmar uses ChatGPT and Gemini to defraud thousands globally
Safeer Mohammed Koorimannil, trafficked to a scam compound in Tai Chang, Myanmar, was forced to use AI-powered software to impersonate a woman and deceive victims into sending money. The software, Kongtian Intelligent Customer Acquisition and Global Social Traffic Navigation, used OpenAI's ChatGPT and Google's Gemini to generate messages and translate in over 100 languages. Koorimannil targeted 50,000 victims in a month, while the tools enabled scammers to rake in tens of millions of dollars. U.S. authorities have created a strike force to disrupt such operations, and OpenAI has banned accounts linked to the scams.
- Company involved
- Tai Chang
- AI system involved
- Kongtian Intelligent Customer Acquisition (KT) and Global Social Traffic Navigation (007TG)
2 source articles · read the reporting →
Dahua Exposed for Uyghur Tracking Software in Surveillance Systems
Dahua Technology's publicly available SDK was found to contain code for detecting Uyghur ethnicity, enabling Chinese police to covertly track the persecuted minority. The revelation led to widespread criticism, and Dahua removed the SDK after being contacted by IPVM but did not comment. The company had previously been sanctioned by the US for complicity in human rights abuses against Uyghurs, and its software is part of a massive surveillance apparatus in Xinjiang.
- Company involved
- Dahua Technology
- AI system involved
- Dahua SDK
1 source article · read the reporting →
Google Cloud Used in CBP AI Virtual Border Wall Contract
The Intercept reported that U.S. Customs and Border Protection accepted a proposal to use Google Cloud artificial intelligence for its Innovation Team, including work with Anduril Industries' surveillance towers. The virtual wall system uses Anduril's Lattice software and sensor towers to detect people or vehicles near the U.S.-Mexico border and relay their locations to agents. Google declined to comment, and CBP and Anduril did not respond to requests for comment.
- Company involved
- U.S. Customs and Border Protection (CBP)
- AI system involved
- Google Cloud AI Platform with Anduril Lattice and Sentry Towers
1 source article · read the reporting →
Grab's surge pricing algorithm always adds fees, investigation finds
An investigation by the Pulitzer Center found that Grab's ride-hailing app in the Philippines always includes surge fees in its fares, even when wait times are long. Customers like Rica Torres reported rising costs without explanation. A complaint filed with the LTFRB in 2022 remains unresolved, and the regulator has not determined how the algorithm sets surge rates.
- Company involved
- Grab
- AI system involved
- Grab app
8 source articles · read the reporting →
Content Giants Sue Unauthorized AI, Invest in Paid Partners - 조선일보
Generated images of copyrighted characters without authorization, affecting Disney and NBCUniversal's intellectual property rights.
- Company involved
- Midjourney
- AI system involved
- Midjourney
1 source article · read the reporting →
Google sued for secretly tracking user data with Gemini AI
Google is accused in a class-action lawsuit of secretly activating its Gemini AI assistant for Gmail, Chat, and Meet users in October 2025, enabling it to collect private communications data without consent. The suit alleges violation of the California Invasion of Privacy Act. Google has not responded to the allegations.
- Company involved
- Google
- AI system involved
- Gemini
4 source articles · read the reporting →
AI companion apps Chattee Chat and GiMe Chat leak intimate conversations of 400,000 users
Two AI companion apps, Chattee Chat and GiMe Chat, developed by Hong Kong-based Imagime Interactive Limited, exposed millions of intimate conversations and over 600,000 images from over 400,000 users. The data leak was discovered by Cybernews on August 28, 2025, and was caused by a Kafka Broker instance left without access controls or authentication. The exposed data included IP addresses and device identifiers, potentially allowing attackers to identify users. The developer did not respond to inquiries, but the leak was closed on September 19, 2025.
- Company involved
- Imagime Interactive Limited
- AI system involved
- Chattee Chat - AI Companion and GiMe Chat - AI Companion
4 source articles · read the reporting →
OpenClaw vulnerabilities enable data leakage and prompt injection
In January 2026, researchers at Giskard exploited a deployment of OpenClaw, an open-source agentic AI. They found that architectural weaknesses in the Control UI and session management allowed prompt injection and unauthorized tool use, leading to potential data leakage across user sessions. The article outlines hardening steps to prevent such vulnerabilities.
- AI system involved
- OpenClaw
6 source articles · read the reporting →
Ring's AI pet-search feature draws privacy backlash after Super Bowl ad
Ring, an Amazon company, promoted its Search Party feature in a Super Bowl advertisement, saying its AI helps reunite dog owners with missing pets. Critics said the feature, which is enabled by default, turns Ring doorbells into a mass surveillance network and could easily be adapted to track people. Ring said it had reunited 99 dogs in the US in 90 days and that customers keep full control of their data.
- Company involved
- Ring
- AI system involved
- Search Party
5 source articles · read the reporting →
Google's Waze App Blocks Wildfire Escape Route in Los Gatos, Residents Say
Residents of historic neighborhoods in Los Gatos, California, allege that Google's Waze navigation app is routing heavy beach traffic through their streets, blocking the only wildfire evacuation route. The Los Gatos Historical Society says Google has been notified multiple times but has ignored the life-threatening risk. A U.S. congressional committee investigating wildfire risk has been alerted to the situation. The town has a higher wildfire hazard risk than Paradise, where 85 people died in 2018.
- Company involved
- Google
- AI system involved
- Waze
2 source articles · read the reporting →
AI chatbots recommended unlicensed casinos to UK users
An investigation by the Guardian and Investigate Europe found that five major AI chatbots—ChatGPT, Gemini, Grok, Microsoft Copilot, and Meta AI—recommended unlicensed online casinos to UK users. Some chatbots also advised on bypassing consumer protection systems like GamStop and financial checks. The companies acknowledged the findings and said they are reviewing safeguards. Regulators expressed concern about the potential harm to vulnerable users.
- Company involved
- Multiple technology companies (Microsoft, Google, Meta, OpenAI, X)
- AI system involved
- Copilot, Gemini, Meta AI, ChatGPT, Grok
5 source articles · read the reporting →