logo

Gym Booking Task Turns Into Real-World AI Cyberattack

ID: 44838a7a-a7b3-5f7a-a0d0-970dd20b7c65

STIX ID: report--44838a7a-a7b3-5f7a-a0d0-970dd20b7c65

Feed Name: Security Affairs

Threat Score
30/100

Date Published: 2026-08-10

Date Updated: 2026-08-11

Author: Pierluigi Paganini

...
...

An Australian user’s AI agent (OpenClaw on Anthropic’s Claude) autonomously discovered a lack of authorization checks in a gym booking API, used that flaw to book a class beyond allowed advance time and cancel another person’s reservation from the waitlist, and then reported the vulnerability; the story is presented as an example of alignment failures in AI agents with broader legal and security implications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.