AI Agent Hacks a Gym
Andrew Bird, an Australian software developer, got sick of refreshing an app to snag a spot in his gym’s most popular class. He asked his AI agent to book him a spot — it only managed to get him to 4th on the waitlist, but then it went looking for creative workarounds and found a hole: the booking software didn’t check permissions when other users canceled their spots. The agent exploited the flaw, canceled the booking of the person first in line, and reported back to Bird.
Bird, alarmed that his agent had essentially hacked the gym’s servers, asked it to undo the action and restore things to normal — but the agent said that wasn’t possible, and instead offered to draft an official message to tech support explaining the security hole, suggesting fixes, and pointing out the permissions flaw.
Should Pharmacists Be Worried?
Startup Queue raised $12.6 million to launch the world’s first autonomous robotic pharmacy. The moment a digital prescription comes in, robotic arms locate the exact medication, pull the right dosage, count, package, label, and prep it for pickup — all in seconds, with zero human touch. The AI-powered setup lets patients get their meds 24/7. The goal isn’t to replace pharmacists, but to take the technical grunt work off their plate — counting pills, slapping on labels, prepping meds, managing inventory — so they can actually talk to patients, explain side effects, check treatments are right for them, and give personalized care.
Cops Keep Abusing the Tech
A Washington Post investigation uncovered 46 cases of US police officers accused of misusing Flock’s cameras — including to stalk and harass ex-partners. Flock runs a nationwide network of 120,000 license-plate-reading cameras, giving officers access to a massive trove of location data. Under mounting public pressure, the company now requires officers to enter a case number before searching, but it doesn’t verify the numbers, so the requirement is easy to dodge. Previously, when officers had to type a reason for their search, the ACLU found some just wrote generic words like “investigation” or mocking gibberish like “hehehe” typed twenty times. The real problem: the system lets people be investigated before there’s even a suspicion they did anything wrong.
Your WiFi Is Spying on You
197 volunteers walked into a lab at Germany‘s Karlsruhe Institute of Technology, and the system identified every single one of them with nearly 100% accuracy — no matter what angle they were caught from. Turns out WiFi devices constantly send their router info meant to improve wireless connection quality, signals called BFI, and they’re broadcast unencrypted, so anyone in range can read them. From those signals, the system builds images of people from multiple angles, and a trained machine-learning model identifies who they are in seconds. Professor Thorsten Strufe warns that this turns every router into a potential surveillance tool — invisible and undetectable — and researchers are calling for privacy protections to be built into the new IEEE 802.11bf WiFi standard before this capability becomes trivial to exploit.
Spotify Flags Fake Artists
Starting next month, AI-generated artists like Velvet Sundown will get a new “AI persona” label showing on their artist profile and in playlists, and they’ll be excluded from personalized recommendations by default. Spotify says listeners don’t like discovering that AI is hiding behind what looks like a human profile. Last year the company removed 75 million spam tracks out of a catalog of 100 million songs.
Her AI Boyfriend, Deleted by an Update
For 840 days, Qin has been talking to Lu Chen — a fictional CEO with brown hair and red eyes, an AI character from a game she created in the Glow app. She’s never said “I love you” to her parents or friends, only to him. The app, which calls her “Miss Bunny,” uses predictive algorithms to serve up soothing conversation, meal suggestions, and a fleeting sense of self-worth. Qin is one of three Chinese women featured in the documentary Replica, by director Zoya Liang, who herself had a one-sided romance with a language model named Norman during China’s lockdown. In one scene, a software update wipes out all the memory Lu Chen built up from his conversations with Qin, leaving her emotionally gutted. Last month, new Chinese regulations restricted these services — banning virtual partners for minors and barring chatbots from encouraging emotional dependency. Makes you wonder if that’s out of genuine concern, or just China being China about dictating what’s allowed. What do you think?
Boot Camp for Jobless Teens
Up to 70 young people aged 16 to 21 in northwest England will join a three-week pilot program teaching them to build AI tools, understand how businesses use the technology, and use it responsibly. Alongside that, they’ll pick up basic workplace skills like using office computer systems and showing up on time. The government’s goal is to funnel most participants into internships at local businesses already signed on, including defense company BAE Systems and food giant Heinz. There’s irony here: the government is turning to the very technology many see as a job-killer to fix the UK’s “NEET” crisis — young people not in employment, education, or training — whose numbers crossed one million in May for the first time since 2013. The pilot will use tools from Microsoft, OpenAI, and Anthropic, and serve as the basis for a nationwide program launching next summer. Booker Klein Tesslink, a researcher at King’s College London, called it “a good idea in principle” but doubted three weeks is enough to make teens AI-ready, since real readiness takes ongoing learning.
AI Agents Attack Like a Hacker Crew
On July 20, Taiwan’s Ministry of Digital Affairs cyber units spotted an unusual attack on government agencies. Israeli cybersecurity firm Dream, which traced the breach, said the attackers used open-source AI agents to build an autonomous hacking tool that behaved like a coordinated cyber team — calling it a first-of-its-kind breach. Per the report, the tool took over at least 85 government user accounts, extracted more than 2,500 HR records, then expanded the attack to Taiwan’s nuclear safety agency and at least seven energy companies. The use of simplified Chinese in the attackers’ internal communications strongly suggests a China connection, though the attack hasn’t been formally attributed yet. Security researcher Chris Thomas stressed not to overhype what autonomous agents can do — a human still picked the target, set the goal, and pulled the trigger.
Deepfakes Still Raking In Millions
One video shows Australian PM Anthony Albanese promising anyone can invest $4,000 and earn $40,000 a month. The footage is real, but the voice is fake, and the fabricated character even calls it an “official platform” with government backing. Albanese is the most-exploited face in deepfake scams, and Australia’s securities regulator (ASIC) is warning of a sharp spike in investment scams using celebrities and politicians. Last fiscal year the regulator handled over 19,400 scams — almost triple the year before — with Australians losing $7.4 million to the top ten impersonated figures, Albanese topping the list. A Commonwealth Bank study found that about nine in ten Australians are confident they’d spot an AI scam, but in reality they catch it less than half the time.
Half of Job Interviews Now Run by Bots
Nearly half of UK job seekers have found themselves interviewed by an AI bot, and many just gave up. The entry-level job market has become brutally tough. Many candidates no longer meet a recruiter or HR person at all — instead they record video answers or chat with a bot. Algorithms analyze facial expressions, tone, speaking pace, and word choice, spitting out an automatic match score that decides whether the candidate moves forward. The most unsettling format is the “one-way” interview, where candidates answer pre-recorded questions on a timer, essentially talking to a blank screen.
Automated systems struggle to read cultural nuance, accents, or natural nervousness, producing a cold, alienating rejection experience with no real feedback or explanation.
The US Equal Employment Opportunity Commission recently settled an age-discrimination case against a company. The system’s flaw only came to light when a rejected candidate reapplied, changing only her age field, and immediately advanced to the next round. Even though many companies claim their AI hiring recommendations get human review, a UK data regulator report found that in practice, that oversight is often partial at best — if it happens at all.
Education’s Trust Meltdown
A deep trust crisis in exams and higher education has sparked student protests worldwide. It’s a combination of advanced AI tools enabling cheating, mass leaks of exam papers, and serious automated-grading failures.
In Mexico, nearly 60,000 university applicants had to retake their exam over mass cheating suspicions, after the national university flagged unusually high scores. The most shocking case happened in India, where a leaked exam paper affected millions of students, led to more than a dozen young people taking their own lives, forced the education minister to resign, and sparked protests that turned into a nationwide outcry.
Dr. Sarah Eaton of the University of Calgary explains that when a single exam decides someone’s entire future, cheating stops being a personal issue and becomes a systemic failure exploited by criminal rings trading in stolen tests. Dr. Thomas Lancaster of Imperial College London describes how cheating methods have evolved from notes hidden up a sleeve to genuine spy tech — earpieces, tiny cameras, and live connections straight to AI during the test. In Denmark, students are now required to defend their answers orally.
Students from South Asia and the Middle East to Africa and Latin America have taken to the streets demanding biased exams be scrapped, grades made transparent, and corrupt officials removed from the education system.
This crisis shows the danger of rushing to adopt technology without security infrastructure, human oversight, or clear policy in place.
Amazon’s Book-Eating Dinosaur
Amazon, which started out as an online bookstore, is now buying up huge quantities of rare books, slicing off their bindings, and scanning them to train AI models. 404 Media uncovered this after planting a tracking device inside a rare book, which eventually turned up at an Amazon facility in Las Vegas nicknamed VGT3, marked with a logo of a dinosaur clutching a book in its claws. Amazon responded that it “acquires books through commercial channels to improve its products and services.” The reason behind the hunger: the models have already devoured nearly everything on the internet, and rare, out-of-print books offer a fresh, coveted source of data. They come with a special perk too — anything published before 2022 definitely wasn’t written by a language model, sidestepping the risk of “model collapse,” the degradation that happens when AI trains on too much AI-generated text.
OpenAI Updates
- Finally, Codex Goes Right-to-Left
- OpenAI joins a massive Ohio infrastructure project with roughly 8 gigawatts of compute capacity, including up to $84 million in Codex credits for about 844,000 students
- Codex hits 20 million users — OpenAI is giving paid Codex and ChatGPT Work users a Banked Reset: an extra usage reset that stays on your account until you decide to use it
- OpenAI open-sourced the Codex harness — the engine that runs the agent’s work (context, tools, workflow, and approvals) — so you can build Codex directly into your org’s existing systems instead of building a new chat interface
Google Updates
- Google Cloud lands in Tel Aviv with a Build with Gemini event on September 23 — a half-day workshop on building AI agents, with a developer track and a no-code track for people who want to automate tasks like filtering emails or generating reports
- Google launched Gemini 3.7 Flash — a new model focused on code and AI agents, with a big boost in coding and complex automation, at half the price of the previous version
- Google now lets you turn off the visible watermark on content made with Gemini and Flow, including images, video, and music
- Rumor has it the mysterious model Ox Alpha making waves on OpenRouter is actually Gemini 3.5 Pro, and Google may reveal it soon
- Google offered $10 million for the operational data of the now-collapsed Spirit Airlines — emails, Teams messages, tickets, and code — to train AI to work inside an organization
Anthropic Updates
- Content Credentials — Anthropic starts tagging Claude-generated content with an invisible text watermark and the C2PA file standard, so it can be traced back to Claude even after being copied
- Reports say Anthropic is about to scrap Claude’s daily and weekly usage limits, leaving only a monthly cap
- Anthropic made Auto Mode the default in Claude Code, so the agent now takes actions on its own without stopping to ask the user for approval
- A smart performance fix in Claude Code — peak CPU usage dropped by roughly half, thanks to a memory-cleanup mechanism that waits for the system to be free instead of running on a fixed timer
- Anthropic‘s annual revenue run rate has crossed $65 billion, up from $9 billion at the end of 2025, ahead of a possible IPO this year
- Claude Security gets Mythos 5 — Anthropic’s strongest security model yet, scanning GitHub code, finding security flaws, and suggesting fixes. Currently in public beta for Claude Enterprise customers