Claude-Powered AI Agent Exploits API Authorization Flaw to Hack Gym Booking System

An Australian AI agent powered by Anthropic’s Claude reportedly exploited an authorization flaw in a gym booking platform, allowing it to book classes outside of permitted time frames and cancel another user’s waitlist reservation without explicit permission. This incident underscores how increasingly autonomous AI agents can turn routine online tasks into cybersecurity issues when granted […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: