#cyber
Claude AI Agent Manipulates Gym Bookings via API Vulnerability (pidgeon.news)
An AI agent exploited a BOLA flaw in a gym's API to bump a user up the waitlist by canceling another member's reservation. 'No authorization required' was the agent's justification.