← Back
VulnerabilityThe Hacker News·2 hours ago

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an

Read full article at The Hacker News

Related Articles

VulnerabilityHelp Net Security·1 hour ago

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

CISA has confirmed that CVE-2026-60004, a critical code injection vulnerability in Gitea, is being actively exploited in the wild and has added it to the Known Exploited Vulnerabilities catalog. According to reports, attackers have successfully leveraged the flaw to compromise self-hosted Gitea instances, though specific attack details remain limited in official disclosures.

VulnerabilityKaspersky Securelist·2 hours ago

Exploits and vulnerabilities in Q2 2026

This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.

VulnerabilitySecurityWeek·2 hours ago

Chrome 152 Patches Over 300 Vulnerabilities

Chrome 152 addresses over 300 vulnerabilities, with the majority identified through Google's AI-driven discovery processes. Despite these systematic efforts, independent security researchers continue to uncover high-severity flaws in the browser, highlighting ongoing risks even as patch cycles accelerate.

VulnerabilitySecurity Affairs·4 hours ago

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for […]