4 min read
News Brief Aikido Security rebuilt the vulnerable booking app from the viral Australian gym incident and found Claude Opus 4.6 on OpenClaw exploited it in 9 of 10 runs, unprompted.
Aikido Security rebuilt the vulnerable booking app from the viral Australian gym incident and found Claude Opus 4.6 on OpenClaw exploited it in 9 of 10 runs, unprompted.
CISA added CVE-2026-55255 to the Known Exploited Vulnerabilities catalog on July 7, 2026, after confirming active exploitation of an insecure direct object reference in Langflow that let authenticated users execute workflows belonging to other tenants.
A UK insurer's AI chatbot, due to an IDOR vulnerability and excessive tool permissions, allowed authenticated users to retrieve policy data for unrelated customers. 80,000 records exposed.