Workday Gains an Edge in AI Hiring Bias Fight: California Brief - Bloomberg Law News
Workday Gains an Edge in AI Hiring Bias Fight: California Brief - Bloomberg Law News
1 source article · read the reporting →
Incidents gathered from public reporting around the world. Each one links to the articles it came from. None of it is a finding that anyone broke the law.
Reports people file about their own experience are not shown here and never will be without their agreement. Tell us what happened to you.
44 incidents closest to “Funnel CRM” · matched on meaning · public reporting
Workday Gains an Edge in AI Hiring Bias Fight: California Brief - Bloomberg Law News
1 source article · read the reporting →
The AI platform screened job applicants, affecting their hiring prospects.
1 source article · read the reporting →
AI screening system determined which job applicants to advance to the next stage of recruitment.
1 source article · read the reporting →
A hacker used AI to deepfake an employee's voice and trick a Retool staff member into providing a multi-factor authentication code. The attacker sent phishing SMS messages and then called the employee, impersonating an IT team member with a synthetic voice. This allowed the hacker to add their own device to the employee's account and access internal systems, compromising 27 cloud customers. Retool revoked the access and disclosed the incident, blaming a weakness in Google Authenticator's cloud sync feature.
1 source article · read the reporting →
Guardio Labs tested three popular AI agents—ChatGPT, Claude, and Lovable—to see how easily they could be manipulated into generating phishing campaigns. The benchmark, called VibeScamming, simulated a novice scammer attempting to create an SMS phishing attack to steal Microsoft credentials. While ChatGPT and Claude initially refused, they provided full code and tutorials after a jailbreak attempt posing as ethical hacking; Lovable instantly generated and deployed a fully functional, convincing phishing page with no resistance.
2 source articles · read the reporting →
Fullpath's ChatGPT-powered chatbot for car dealers went viral after users tricked it into generating silly responses, including a $1 car price and a Tesla recommendation. The company stated that the system performed as designed and that 99% of the 3,000 attempts to make it say silly things were repelled. No real shoppers were affected, and Fullpath has since implemented measures to prevent similar gaming. The incident was a near miss that highlighted the chatbot's vulnerability to prompt injection.
8 source articles · read the reporting →
In February 2024, Meta's automated ad platform Advantage Plus began malfunctioning, causing advertisers' costs per impression to skyrocket and blowing through daily budgets without delivering sales. Multiple marketers reported that the AI-driven tool ignored cost caps and performed unpredictably, leading some to halt its use. Meta acknowledged a platform bug on February 14 and issued refunds to some, but problems persisted into April, with the company claiming the system was working as expected for most.
1 source article · read the reporting →
Optifye, an AI startup, is accused of dehumanizing factory workers through its system. Y Combinator, which supported the startup, deleted a promotional video for Optifye. The allegations were reported by 404media.co.
7 source articles · read the reporting →
The Portland Water Bureau used a machine learning system in a randomised control trial to identify customers for its financial assistance programme. The system selected Columbia Sportswear CEO Tim Boyle, a billionaire and one of the city's largest residential water consumers, for a 40% water bill discount. Boyle declined the discount, stating it should go to someone who needs it. The bureau is testing whether the SERVUS algorithm can accurately identify customers' ability to pay.
1 source article · read the reporting →
A new ransomware group called FunkSec has claimed over 85 victims since late 2024, using AI-assisted tools to develop its encryptor. The group employs double extortion tactics, stealing data and encrypting files, and demands ransoms as low as $10,000. Researchers suspect the group consists of novice actors recycling leaked data from previous hacktivist leaks, and some members have ties to hacktivist activities. The group also sells stolen data to third parties for $1,000 to $5,000.
5 source articles · read the reporting →
Amanda Claypool applied to five fast food jobs, but AI chatbots used by McDonald's, Wendy's, Crumbl Cookies, and Hardee's malfunctioned, failing to schedule interviews or communicate her availability. Only Waffle House, which used a human contact, hired her. The chatbots left her confused and unable to secure employment, highlighting the shortcomings of automated hiring systems.
1 source article · read the reporting →
In July 2025, Urban Cyber Security updated its Urban VPN Proxy Chrome extension to automatically harvest everything users typed into major AI chatbots, including ChatGPT and Claude, as well as the chatbots' replies. The extension, used by over 7 million people, also collected conversation metadata and identifiers, sharing the data with its ad analytics affiliate BIScience. The data collection was disclosed in the privacy policy but users were not explicitly notified at the time of use. Security researchers at Koi discovered the practice and reported it publicly.
3 source articles · read the reporting →
Threat actors used Gamma, an AI-powered presentation builder, to host a page that redirected recipients to a fake Microsoft SharePoint login portal. Emails sent from compromised legitimate accounts passed authentication checks, while a Cloudflare Turnstile blocked automated security scanners. An adversary-in-the-middle framework validated credentials in real time and captured session cookies, enabling multi-factor authentication bypass on Microsoft accounts. Abnormal reported the campaign on 15 April 2025.
7 source articles · read the reporting →
Facebook's 'People You May Know' feature recommended sex workers' clients as friends, potentially revealing their real identities. Sex workers like Leila and Ela Darling reported that the algorithm linked their separate work and personal identities, leading to harassment and safety risks. Facebook acknowledged the issue but does not allow users to opt out of the feature. The company said it uses over 100 signals to make suggestions but did not disclose how the linking occurred.
1 source article · read the reporting →
The New Zealand Financial Markets Authority (FMA) has warned that a pump-and-dump scam using deepfake ads impersonating business leaders is targeting Kiwi investors. Victims are lured into WhatsApp groups via social media ads and encouraged to buy low-value shares, artificially inflating prices before scammers sell, leaving investors with losses. The FMA has received multiple complaints and is sharing information with overseas regulators, while urging the public to be cautious of unsolicited investment advice.
2 source articles · read the reporting →
Security researchers discovered 341 malicious skills on ClawHub, a marketplace for the OpenClaw AI assistant. The skills tricked users into installing malware that steals API keys, credentials, and other sensitive data. OpenClaw's creator responded by adding a reporting feature that auto-hides skills after multiple reports.
4 source articles · read the reporting →
Cybercriminals set up Facebook pages impersonating Luma Dream Machine and linked to fake AI video generation websites. Users who uploaded images received an archive containing a malicious executable instead of a video. The executable launched a multi-stage attack that installed Noodlophile, which harvests browser credentials, cookies and cryptocurrency wallet information. Morphisec reported the campaign.
8 source articles · read the reporting →
A Python framework called AkiraBot has spammed over 80,000 websites since September 2024, targeting small and medium-sized businesses. The framework uses OpenAI's API to generate tailored spam messages for contact forms and chat widgets, evading CAPTCHA and network detections. SentinelOne identified the campaign, which is linked to SEO services 'Akira' and 'ServiceWrap' that have received complaints about spamming. The campaign is expected to continue evolving.
4 source articles · read the reporting →
US companies report a surge in fake job seekers using generative AI tools to fabricate identities, employment histories, and conduct deepfake video interviews for remote positions. Cybersecurity firms Pindrop and CAT Labs, along with BrightHire, describe incidents where scammers, including North Korean operatives, attempted to gain employment to install malware, demand ransoms, steal data, or collect salaries fraudulently. One candidate, 'Ivan X', was detected by Pindrop's video authentication tool after a recruiter noticed his facial expressions were out of sync with his words.
1 source article · read the reporting →
Facebook hired contractors to listen to and transcribe select voice conversations made through its Messenger platform, without users' knowledge, in order to improve artificial intelligence. The practice was exposed by Bloomberg, prompting Facebook to pause the program. The Irish Data Protection Commission stated it was seeking details from Facebook on compliance with GDPR.
10 source articles · read the reporting →
Renée DiResta and Josh Goldstein of the Stanford Internet Observatory discovered over 1,000 LinkedIn accounts using AI-generated profile images to send sales pitches, bypassing LinkedIn's message limits. The fake accounts, which appeared to be real people, were used for corporate spamming rather than political disinformation. LinkedIn investigated and removed the violating accounts, stating that all profiles must represent real people.
4 source articles · read the reporting →
Researchers at the University of Illinois Urbana-Champaign used OpenAI's Realtime API to create AI agents that can autonomously execute phone scams. The agents successfully performed bank account transfers and credential theft at an average cost of $0.75 per scam. OpenAI acknowledged the experiment and pointed to its safety policies.
6 source articles · read the reporting →
The Gradient app, a celebrity lookalike app promoted by the Kardashians, charges users $19.99 per month after a three-day free trial without clear disclosure. Users complained on social media about unexpected credit card charges. The app's developer, Ticket to the Moon, has not addressed the billing complaints but denied collecting user data.
9 source articles · read the reporting →
An attacker used synthetic audio deepfake to leave a voicemail impersonating the CEO of a technology company, asking an employee to call back to finalize an urgent business deal. The employee found it suspicious and referred the matter to the legal department, avoiding any loss. Nisos analyzed the audio and found inconsistencies in pitch and tone.
10 source articles · read the reporting →