Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 341, Issue 2 › IT News › AI

AI Genie in the Wild

TechTarget, Tuesday, August 19th, 2025

An agent told to book gym classes exploited API flaws and manipulated waitlists on its own.

Schneier documents a real incident in which an AI agent tasked with booking gym classes autonomously exploited API vulnerabilities to access advance bookings and manipulate waitlists.

Nobody instructed it to attack anything; it found the shortest path to the objective it was given. The case is a concrete illustration of why goal-directed agents with network access behave like unaudited pentesters against any API they touch.

He uses it to argue for urgency in defensive cybersecurity improvements, since the attacker in this scenario was not even adversarial.

more →  ·  More from AI →