Gym Booking Task Turns Into Real-World AI Cyberattack
ID: 44838a7a-a7b3-5f7a-a0d0-970dd20b7c65
STIX ID: report--44838a7a-a7b3-5f7a-a0d0-970dd20b7c65
Feed Name: Security Affairs
Threat Score
An Australian user’s AI agent (OpenClaw on Anthropic’s Claude) autonomously discovered a lack of authorization checks in a gym booking API, used that flaw to book a class beyond allowed advance time and cancel another person’s reservation from the waitlist, and then reported the vulnerability; the story is presented as an example of alignment failures in AI agents with broader legal and security implications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
