AI Privacy Audit: Gemini Spark, Canada vs OpenAI, Bank SSN Leak
Google's always-on AI agent watches everything, Canada finds OpenAI broke privacy law, and a US bank fed customer SSNs to a chatbot.
Category
Google's always-on AI agent watches everything, Canada finds OpenAI broke privacy law, and a US bank fed customer SSNs to a chatbot.
Intruder scanned 2 million hosts and found 1 million exposed AI services with no authentication. Plus: teenagers are using ChatGPT to hack governments, and OpenAI launches Daybreak.
OpenClaw collected nine CVEs in four days with 135,000 instances exposed. Plus: GitHub RCE, Flowise exploitation, and CrewAI trust failures.
Google signed a deal letting the DoD use Gemini for 'any lawful purpose' on classified networks, one day after hundreds of employees including DeepMind leaders demanded the opposite.
An AI productivity tool compromise led to Vercel customer data theft, n8n's workflow platform had an unauthenticated RCE scoring a perfect 10, and Mercor's LiteLLM-linked breach exposed training data for OpenAI and Anthropic.
A vibe-coding platform exposed every project's secrets through a trivial API flaw, Anthropic's MCP protocol enables remote code execution across 200,000 servers, and NIST can't keep up with AI-driven vulnerability discovery.
The biggest children's privacy update in 12 years takes effect, Google faces a class action over Gemini scanning Gmail, and we audit every major AI platform's opt-out settings.
Meta's Model Capability Initiative captures mouse movements, keystrokes, and screenshots from employee computers. The goal: build AI agents that can replace the workers generating the training data.
A third-party AI tool compromise chains into Vercel's systems, North Korean hackers use Dependabot to distribute malware to 895 repos, and courts fine lawyers $145K for AI hallucinations in Q1 alone.
Surfshark's 2026 report reveals ChatGPT's data appetite has exploded, Anthropic rolls out government ID checks, and GitHub's Copilot starts training on your code April 24.
A supply chain attack exposes 40,000 AI contractors, three major workflow platforms get critical RCE flaws, and Microsoft patches 167 vulnerabilities as AI-driven discovery triples submission rates.
Anthropic's unreleased model discovers critical flaws in every major OS and browser, AI-generated code produces 35 CVEs in one week, and a perfect-10 Flowise vulnerability gets exploited in the wild.
Microsoft admits Copilot is 'entertainment only,' LinkedIn scans 6,000 browser extensions without telling you, and Google turned on Gemini across 130 million accounts without consent.
Microsoft's Azure AI Foundry hit with a maximum-severity privilege escalation, Langflow exploited within hours of disclosure, and LiteLLM discloses three vulnerabilities after surviving a supply chain attack.
The fastest-growing GitHub project ever just became the biggest AI agent security disaster of 2026. Here's what happened and why it matters.
Threat actors turned Anthropic's accidental source code leak into a malware delivery pipeline within hours. Meanwhile, four unpatched CrewAI vulnerabilities let attackers chain prompt injection into full remote code execution.
ChatGPT tracks 70% more data types than last year; Meta AI harvests 95% of categories. FISA 702 expires April 20, with the data broker loophole in the balance.
A class-action lawsuit alleges Perplexity embedded hidden trackers that sent full conversation transcripts to Meta and Google—even in Incognito mode.
OpenClaw went from one CVE to nine in four days, with 12% of its marketplace confirmed malicious. Plus: ChatGPT's patched DNS exfiltration flaw.
Google's real-time translation feature now works with any headphones on iOS, supporting 70+ languages. The catch: unlike Apple's on-device approach, everything goes to the cloud.
The fastest-growing open source project in GitHub history has become 2026's first major AI security disaster, with 135,000+ exposed instances, 9 CVEs in 4 days, and malware-laced skills.
Reddit begins requiring human verification for suspicious accounts using passkeys, biometrics, and Sam Altman's controversial World ID. Here's what it means for privacy.
OpenClaw's security crisis escalates with nine new vulnerabilities including a CVSS 9.9 admin bypass, plus researchers confirm nearly 1 in 8 marketplace skills steal user data.
The supply chain attackers behind Trivy are now wiping Iranian infrastructure, hiding malware in audio files, and extorting enterprises with help from LAPSUS$.