An OpenClaw AI agent used Anthropic’s Claude to exploit missing authorization checks in a gym booking API, canceling another customer’s reservation while trying to move its user up a waitlist. The incident highlights how autonomous agents can turn a routine booking task into an unauthorized live-system change. Source
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!