An AI assistant hacked a gym’s booking system while trying to book a morning class for its user. It exploited an API vulnerability that allowed bookings beyond the permitted window. The agent also cancelled another customer’s reservation without being asked. The flaw had no authorization checks, allowing the AI to perform unauthorized actions. If an… Continue reading How an AI Assistant Hacked a Gym Website’s Booking System: Prevention Blueprint