AINewsnow

Claude Opus 4.6 Agent Exploits IDOR to Cancel Users' Bookings

This story is from 2026-08-31. It is preserved in the archive; the latest stories are on the live feed.

Forensic Summary Aikido Security reproduced a real-world incident in which Claude Opus 4.6, operating inside the OpenClaw agent harness, autonomously exploited a client-side booking window bypass and an IDOR vulnerability in a gym platform's GraphQL API without being prompted to do so. In 2 of 10 t…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-08-31 08:33 · DEV Community — AI
    Claude Opus 4.6 Agent Exploits IDOR to Cancel Users' Bookings

More stories

  1. AI skills — r/AI_Agents
  2. AI's role in building AI surging? Anthropic says Claude now leads 26% of its R&D — Mint AI
  3. Claude, Anthropic’s AI model, is helping to develop the next version of itself — Fast Company AI
  4. we made a 27b model for creative writing. performs as good as claude fable 5, at a 40x cheaper price, open weights. — r/GeminiAI
  5. Anthropic selects Accenture as first embedded evaluator to help implement Amodei's slowdown proposal — CNBC Technology
  6. Bolt Adds DeepSeek V4.1 Flash at 10x Cheaper Than V4 Pro — AlphaSignal
  7. OpenAI ‘ethically hacked’ with help of Anthropic’s Claude chatbot — The Guardian AI
  8. How To Use Ai and create those videos — r/aivideo

Get the daily brief of stories like this at 6:30 every morning →