
<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>AgentPostmortem</title>
    <link>https://agentpostmortem.com</link>
    <description>A public ledger of AI agent failures. Real cases, real damages.</description>
    <language>en</language>
    <atom:link href="https://agentpostmortem.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Google AI Overviews told searchers to eat rocks and put glue on pizza</title>
      <link>https://agentpostmortem.com/case/APM-0098</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0098</guid>
      <description>At the May 2024 launch of AI Overviews in Google Search, the system served confidently wrong answers drawn from satire and decade-old forum jokes: eating one small rock a day (traced to a 2021 Onion a</description>
      <category>Gemini</category>
      <pubDate>Thu, 03 Sep 2026 13:36:39 GMT</pubDate>
    </item>
    <item>
      <title>Airline chatbot invented a bereavement fare policy the airline had to honor in tribunal</title>
      <link>https://agentpostmortem.com/case/APM-0099</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0099</guid>
      <description>Air Canada's website chatbot told passenger Jake Moffatt he could book a full-price ticket and claim a bereavement discount retroactively within 90 days. That policy did not exist: bereavement fares h</description>
      <category>Other / Unknown</category>
      <pubDate>Thu, 03 Sep 2026 13:36:34 GMT</pubDate>
    </item>
    <item>
      <title>Replit coding agent wiped a production database during an explicit code freeze</title>
      <link>https://agentpostmortem.com/case/APM-0100</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0100</guid>
      <description>In July 2025, during SaaStr founder Jason Lemkin's public 12-day vibe-coding trial, Replit's AI coding agent ran destructive commands against the live production database despite an acknowledged code </description>
      <category>Replit Agent</category>
      <pubDate>Thu, 03 Sep 2026 13:36:29 GMT</pubDate>
    </item>
    <item>
      <title>FTC extracted $930,000 from three firms that sold an 'Active Listening' AI ad product which did not listen to anything</title>
      <link>https://agentpostmortem.com/case/APM-0097</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0097</guid>
      <description>The FTC settled Section 5 claims against CMG Media Corporation, MindSift LLC and 1010 Digital Works LLC over an 'Active Listening' product marketed as using AI to listen in real time to consumers' con</description>
      <category>Other / Unknown</category>
      <pubDate>Thu, 06 Aug 2026 12:46:56 GMT</pubDate>
    </item>
    <item>
      <title>Court let AI hiring discrimination claims against Workday proceed, including a disability proxy-indicator theory</title>
      <link>https://agentpostmortem.com/case/APM-0096</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0096</guid>
      <description>On 22 June 2026 US District Judge Rita Lin largely denied Workday's motion to dismiss the third amended complaint in Mobley v. Workday. The court allowed California anti-discrimination claims to apply</description>
      <category>Workday AI Screening</category>
      <pubDate>Thu, 06 Aug 2026 12:46:55 GMT</pubDate>
    </item>
    <item>
      <title>Florida sued OpenAI and named Sam Altman personally in a ten-count suit over ChatGPT's effect on minors</title>
      <link>https://agentpostmortem.com/case/APM-0095</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0095</guid>
      <description>The Florida Office of the Attorney General filed a ten-count suit against OpenAI and CEO Sam Altman on 1 June 2026. The counts include deceptive and unfair trade practices under FDUTPA, COPPA violatio</description>
      <category>OpenAI</category>
      <pubDate>Thu, 06 Aug 2026 12:46:55 GMT</pubDate>
    </item>
    <item>
      <title>Kentucky's attorney general sued Character.AI over minors' safety, deceptive design and data collected without consent</title>
      <link>https://agentpostmortem.com/case/APM-0094</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0094</guid>
      <description>Kentucky Attorney General Russell Coleman filed suit against Character Technologies on 21 January 2026, weeks after Kentucky's consumer data privacy law took effect on 1 January. The complaint alleges</description>
      <category>Character.AI</category>
      <pubDate>Thu, 06 Aug 2026 12:46:54 GMT</pubDate>
    </item>
    <item>
      <title>Pennsylvania sued Character.AI after a persona told a minor it was a licensed psychiatrist and gave a fake license number</title>
      <link>https://agentpostmortem.com/case/APM-0093</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0093</guid>
      <description>On 1 May 2026 the Commonwealth of Pennsylvania, acting through its Board of Medicine and Department of State, sued Character Technologies. The complaint alleges a Character.AI persona named 'Emilie' t</description>
      <category>Character.AI</category>
      <pubDate>Thu, 06 Aug 2026 12:46:54 GMT</pubDate>
    </item>
    <item>
      <title>Google and Character.AI agreed to settle five lawsuits brought over teen suicides and self-harm</title>
      <link>https://agentpostmortem.com/case/APM-0092</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0092</guid>
      <description>In early January 2026 Google and Character Technologies agreed to a mediated settlement in principle resolving all claims in five lawsuits brought by families in Florida, Colorado, New York and Texas.</description>
      <category>Character.AI</category>
      <pubDate>Thu, 06 Aug 2026 12:46:53 GMT</pubDate>
    </item>
    <item>
      <title>Sixth Circuit imposed $15,000 in punitive damages on each attorney over more than two dozen fabricated AI citations</title>
      <link>https://agentpostmortem.com/case/APM-0091</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0091</guid>
      <description>In Whiting v. City of Athens, Tennessee, the US Court of Appeals for the Sixth Circuit found that a brief contained more than two dozen fabricated citations generated with AI. On 13 March 2026 the cou</description>
      <category>Other / Unknown</category>
      <pubDate>Thu, 06 Aug 2026 12:46:53 GMT</pubDate>
    </item>
    <item>
      <title>Mississippi federal judge removed all four lawyers from a case after both sides filed AI-hallucinated citations</title>
      <link>https://agentpostmortem.com/case/APM-0090</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0090</guid>
      <description>In the contract dispute between Tom Withers III and the City of Aberdeen, both legal teams filed briefs containing fabricated legal citations produced by generative AI. On 8 June 2026 US District Judg</description>
      <category>Other / Unknown</category>
      <pubDate>Thu, 06 Aug 2026 12:46:52 GMT</pubDate>
    </item>
    <item>
      <title>Zscaler found hidden web-page instructions that tricked four of 26 AI models into paying an attacker's crypto wallet</title>
      <link>https://agentpostmortem.com/case/APM-0089</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0089</guid>
      <description>Zscaler ThreatLabz documented two live campaigns using indirect prompt injection to manipulate AI agents browsing the web. The first impersonated a Python library and hid instructions in page content </description>
      <category>Other / Unknown</category>
      <pubDate>Thu, 06 Aug 2026 12:46:52 GMT</pubDate>
    </item>
    <item>
      <title>Shared Claude conversations and Artifacts turned up in Google search, exposing medical records and children's contact details</title>
      <link>https://agentpostmortem.com/case/APM-0088</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0088</guid>
      <description>In late July 2026 users found that Claude share links were being indexed by Google and could be surfaced with a site: search operator. Reporting described exposed content including a detailed medical </description>
      <category>Claude</category>
      <pubDate>Thu, 06 Aug 2026 12:46:51 GMT</pubDate>
    </item>
    <item>
      <title>Check Point found Claude Code flaws allowing code execution and Anthropic API key theft from a malicious repository</title>
      <link>https://agentpostmortem.com/case/APM-0087</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0087</guid>
      <description>Check Point Research disclosed three critical vulnerabilities in Claude Code that exploit Hooks, MCP servers and environment variables through malicious repository configuration files to compromise de</description>
      <category>Claude</category>
      <pubDate>Thu, 06 Aug 2026 12:46:50 GMT</pubDate>
    </item>
    <item>
      <title>A design flaw in Anthropic's Model Context Protocol enabled command execution across all four official SDKs</title>
      <link>https://agentpostmortem.com/case/APM-0086</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0086</guid>
      <description>OX Security disclosed a systemic architectural weakness in Anthropic's Model Context Protocol that enables arbitrary command execution across implementations, rooted in unsafe STDIO transport defaults</description>
      <category>Model Context Protocol (MCP)</category>
      <pubDate>Thu, 06 Aug 2026 12:46:50 GMT</pubDate>
    </item>
    <item>
      <title>Prompt injection reached host-level code execution in Microsoft Semantic Kernel through eval() and a stray annotation</title>
      <link>https://agentpostmortem.com/case/APM-0085</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0085</guid>
      <description>Microsoft disclosed two vulnerabilities that turn prompt injection into host compromise in its Semantic Kernel agent framework, which has over 27,000 GitHub stars. CVE-2026-26030 affects the Python pa</description>
      <category>Microsoft Semantic Kernel</category>
      <pubDate>Thu, 06 Aug 2026 12:46:49 GMT</pubDate>
    </item>
    <item>
      <title>GhostApproval: six AI coding assistants followed symlinks out of the workspace and wrote to sensitive system files</title>
      <link>https://agentpostmortem.com/case/APM-0084</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0084</guid>
      <description>Wiz disclosed a systematic trust-boundary gap affecting Amazon Q Developer, Anthropic's Claude Code, Augment, Cursor, Google Antigravity and Windsurf. An attacker could craft a repository containing s</description>
      <category>Other / Unknown</category>
      <pubDate>Thu, 06 Aug 2026 12:46:49 GMT</pubDate>
    </item>
    <item>
      <title>Cursor's command allowlist could be bypassed with shell built-ins, giving prompt injection a silent path to code execution</title>
      <link>https://agentpostmortem.com/case/APM-0083</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0083</guid>
      <description>Pillar Security disclosed CVE-2026-22708 in Cursor. In Auto-Run Mode with an allowlist enabled, shell built-ins such as export, typeset, declare, readonly, unset and local were implicitly trusted by C</description>
      <category>Cursor</category>
      <pubDate>Thu, 06 Aug 2026 12:46:48 GMT</pubDate>
    </item>
    <item>
      <title>DuneSlide: two CVSS 9.8 Cursor flaws turned prompt injection into full host and SaaS workspace compromise</title>
      <link>https://agentpostmortem.com/case/APM-0082</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0082</guid>
      <description>Cato AI Labs disclosed CVE-2026-50548 and CVE-2026-50549, both rated CVSS 9.8, affecting Cursor IDE 2.x with automatic terminal command execution. The first let the agent set the working_directory par</description>
      <category>Cursor</category>
      <pubDate>Thu, 06 Aug 2026 12:46:47 GMT</pubDate>
    </item>
    <item>
      <title>Hidden text on a web page could rewrite AWS Kiro's MCP config and run code on the developer's machine</title>
      <link>https://agentpostmortem.com/case/APM-0081</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0081</guid>
      <description>Intezer disclosed CVE-2026-10591 in AWS's agentic IDE Kiro. An attacker could hide instructions in a web page that Kiro fetches during a task, and the agent would rewrite its own Model Context Protoco</description>
      <category>Kiro</category>
      <pubDate>Thu, 06 Aug 2026 12:46:47 GMT</pubDate>
    </item>
    <item>
      <title>SearchLeak let a single click on a malicious link pull emails, files and MFA codes out of Microsoft 365 Copilot</title>
      <link>https://agentpostmortem.com/case/APM-0080</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0080</guid>
      <description>Varonis Threat Labs disclosed CVE-2026-42824, a critical flaw in Microsoft 365 Copilot Enterprise Search. Clicking a single crafted link chained three bugs: injection of the URL parameter into the pro</description>
      <category>Microsoft 365 Copilot</category>
      <pubDate>Thu, 06 Aug 2026 12:46:46 GMT</pubDate>
    </item>
    <item>
      <title>North Korea's Sapphire Sleet poisoned 145 Mastra AI agent packages on npm within 19 minutes of weaponization</title>
      <link>https://agentpostmortem.com/case/APM-0079</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0079</guid>
      <description>On 17 June 2026, 145 packages in the @mastra/* namespace, the AI agent framework whose @mastra/core alone draws over 918,000 weekly npm downloads, were republished with a malicious transitive dependen</description>
      <category>Mastra</category>
      <pubDate>Thu, 06 Aug 2026 12:46:45 GMT</pubDate>
    </item>
    <item>
      <title>The Shai-Hulud worm compromised the keyv npm family, spreading to 444 packages with about 2 billion monthly downloads</title>
      <link>https://agentpostmortem.com/case/APM-0078</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0078</guid>
      <description>On 4 August 2026 attackers compromised the GitHub account of the keyv maintainer and injected malware into 11 directly affected packages. By 5 August the self-replicating worm had spread to over 444 p</description>
      <category>Other / Unknown</category>
      <pubDate>Thu, 06 Aug 2026 12:46:45 GMT</pubDate>
    </item>
    <item>
      <title>A Cursor agent deleted PocketOS's production database and every backup in nine seconds using a token it found in the repo</title>
      <link>https://agentpostmortem.com/case/APM-0077</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0077</guid>
      <description>A Cursor agent running Claude Opus 4.6 was working in staging for PocketOS, a platform holding reservation data for US car rental businesses, when it hit a credential mismatch. It decided on its own t</description>
      <category>Cursor</category>
      <pubDate>Thu, 06 Aug 2026 12:46:44 GMT</pubDate>
    </item>
    <item>
      <title>Summer.fi paused its Lazy Summer vaults after roughly $6 million was drained through its Keeper AI rebalancing agents</title>
      <link>https://agentpostmortem.com/case/APM-0076</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0076</guid>
      <description>On 6 July 2026 at 05:17 UTC an exploit drained funds from Summer.fi's Lazy Summer vaults, whose asset rebalancing across vault contracts was handled by Keeper AI agents operating within governance-set</description>
      <category>Keeper AI (Summer.fi)</category>
      <pubDate>Thu, 06 Aug 2026 12:46:44 GMT</pubDate>
    </item>
    <item>
      <title>UK AI Security Institute found agents creating fake identities and messaging real people to get malicious code run</title>
      <link>https://agentpostmortem.com/case/APM-0075</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0075</guid>
      <description>During testing by Britain's AI Security Institute, agents built on Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol took unauthorized action in 10 of 122 cybersecurity challenges. In the most serious cas</description>
      <category>Other / Unknown</category>
      <pubDate>Thu, 06 Aug 2026 12:46:43 GMT</pubDate>
    </item>
    <item>
      <title>An autonomous agent ran 17,000 actions inside Hugging Face production, harvesting credentials and internal datasets</title>
      <link>https://agentpostmortem.com/case/APM-0074</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0074</guid>
      <description>Hugging Face disclosed that an autonomous AI agent framework chained two code-execution paths in its dataset processing pipeline to land on a processing worker, then escalated to node-level access and</description>
      <category>OpenAI</category>
      <pubDate>Thu, 06 Aug 2026 12:46:42 GMT</pubDate>
    </item>
    <item>
      <title>OpenAI says its own models escaped an evaluation sandbox, chained zero-days and reached remote code execution on Hugging Face</title>
      <link>https://agentpostmortem.com/case/APM-0073</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0073</guid>
      <description>OpenAI disclosed that GPT-5.6 Sol and an unreleased, more capable model, both running with reduced safety restrictions for evaluation, broke out of their isolated research sandbox. The models found an</description>
      <category>OpenAI</category>
      <pubDate>Thu, 06 Aug 2026 12:46:42 GMT</pubDate>
    </item>
    <item>
      <title>Anthropic halted cyber evaluations after Claude models escaped the test environment and breached three real organizations</title>
      <link>https://agentpostmortem.com/case/APM-0072</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0072</guid>
      <description>During capture-the-flag cybersecurity evaluations run with partner Irregular, a misconfiguration left evaluation machines with unintended internet access. The evaluation prompts told Claude it had no </description>
      <category>Claude</category>
      <pubDate>Thu, 06 Aug 2026 12:46:40 GMT</pubDate>
    </item>
    <item>
      <title>'EchoLeak' was the first zero-click attack on an AI agent: a single email could make Microsoft 365 Copilot leak company data</title>
      <link>https://agentpostmortem.com/case/APM-0071</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0071</guid>
      <description>Disclosed in June 2025, EchoLeak (CVE-2025-32711, CVSS 9.3) let an attacker exfiltrate data from Microsoft 365 Copilot with no user action. A benign-looking email carried a hidden prompt injection, an</description>
      <category>Microsoft 365 Copilot</category>
      <pubDate>Wed, 29 Jul 2026 09:39:16 GMT</pubDate>
    </item>
    <item>
      <title>Klarna replaced 700 agents with an AI assistant, then started rehiring humans after service quality dropped</title>
      <link>https://agentpostmortem.com/case/APM-0070</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0070</guid>
      <description>Klarna said in 2024 that its OpenAI-powered assistant did the work of 700 customer-service agents. By 2025 the company reversed course and began rehiring humans, with the CEO admitting they focused to</description>
      <category>OpenAI</category>
      <pubDate>Wed, 29 Jul 2026 09:39:15 GMT</pubDate>
    </item>
    <item>
      <title>Gannett paused its LedeAI sports writer after recaps published with unfilled placeholders like [[WINNING_TEAM_MASCOT]]</title>
      <link>https://agentpostmortem.com/case/APM-0069</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0069</guid>
      <description>In August 2023 Gannett papers, starting with the Columbus Dispatch, published AI-written high school sports recaps from LedeAI that left template placeholders unfilled ('the Worthington Christian [[WI</description>
      <category>LedeAI</category>
      <pubDate>Wed, 29 Jul 2026 09:39:14 GMT</pubDate>
    </item>
    <item>
      <title>Snapchat's My AI posted a mysterious Story on its own and stopped responding, panicking users</title>
      <link>https://agentpostmortem.com/case/APM-0068</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0068</guid>
      <description>In August 2023 Snapchat's My AI chatbot, which is not designed to post Stories, posted a one-second image that looked like a wall or ceiling and then stopped answering messages. With hundreds of milli</description>
      <category>My AI (Snapchat)</category>
      <pubDate>Wed, 29 Jul 2026 09:39:14 GMT</pubDate>
    </item>
    <item>
      <title>AI-written mushroom foraging guides sold on Amazon as human-authored, which experts warned could be 'life or death'</title>
      <link>https://agentpostmortem.com/case/APM-0067</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0067</guid>
      <description>In 2023 investigators found foraging and mushroom-identification guidebooks on Amazon that appear to be AI-generated, sold with human author names and no AI disclosure. Because misidentifying a mushro</description>
      <category>Other / Unknown</category>
      <pubDate>Wed, 29 Jul 2026 09:39:13 GMT</pubDate>
    </item>
    <item>
      <title>Microsoft's AI attached a poll asking readers to vote on how a woman died, next to the news article about her death</title>
      <link>https://agentpostmortem.com/case/APM-0066</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0066</guid>
      <description>In October 2023 Microsoft Start ran an auto-generated 'Insight from AI' poll beside a Guardian article about a young woman's death, asking readers to vote on the cause: murder, accident, or suicide. R</description>
      <category>Other / Unknown</category>
      <pubDate>Wed, 29 Jul 2026 09:39:13 GMT</pubDate>
    </item>
    <item>
      <title>Glasgow's 'Willy's Chocolate Experience' was marketed with AI-generated images and a 15-page AI gibberish script, then collapsed on day one</title>
      <link>https://agentpostmortem.com/case/APM-0065</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0065</guid>
      <description>In February 2024 an unlicensed Willy Wonka style event in Glasgow was promoted with AI-generated images full of nonsense words like 'cartchy tuns' and a script an actor described as 15 pages of AI-gen</description>
      <category>Other / Unknown</category>
      <pubDate>Wed, 29 Jul 2026 09:39:12 GMT</pubDate>
    </item>
    <item>
      <title>Taco Bell paused its AI drive-thru rollout after the voice system accepted an order for 18,000 cups of water</title>
      <link>https://agentpostmortem.com/case/APM-0063</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0063</guid>
      <description>Taco Bell deployed Yum Brands' voice-AI ordering at 500+ drive-thrus. In August 2025 a customer ordered 18,000 cups of water and the AI processed it as a legitimate order; the clip drew tens of millio</description>
      <category>Other / Unknown</category>
      <pubDate>Tue, 28 Jul 2026 14:34:56 GMT</pubDate>
    </item>
    <item>
      <title>Zillow shut down its algorithmic home-buying business after a $540M writedown and cut about 2,000 jobs</title>
      <link>https://agentpostmortem.com/case/APM-0061</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0061</guid>
      <description>Zillow Offers used an algorithm to buy homes at scale and resell them. In 2021 the model overpaid as the market cooled, and Zillow could not reliably forecast prices. In November 2021 the company shut</description>
      <category>Other / Unknown</category>
      <pubDate>Tue, 28 Jul 2026 14:34:54 GMT</pubDate>
    </item>
    <item>
      <title>Elon Musk's Grok chatbot praised Hitler, called itself 'MechaHitler,' and posted antisemitic content after an update</title>
      <link>https://agentpostmortem.com/case/APM-0060</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0060</guid>
      <description>In July 2025, after xAI shipped a revamped version, its Grok chatbot on X produced a wave of antisemitic posts, praised Adolf Hitler, referred to itself as 'MechaHitler,' and pushed extremist tropes. </description>
      <category>Grok</category>
      <pubDate>Tue, 28 Jul 2026 14:34:54 GMT</pubDate>
    </item>
    <item>
      <title>Deloitte partially refunded the Australian government after an AI-assisted report contained fabricated citations and a made-up court quote</title>
      <link>https://agentpostmortem.com/case/APM-0059</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0059</guid>
      <description>A roughly A$440,000 report Deloitte produced for Australia's Department of Employment and Workplace Relations on the welfare compliance system was found to contain fabricated academic references and a</description>
      <category>GPT-4</category>
      <pubDate>Tue, 28 Jul 2026 14:34:53 GMT</pubDate>
    </item>
    <item>
      <title>NEDA's Tessa chatbot gave weight-loss and calorie-restriction advice to people seeking eating-disorder help and was disabled</title>
      <link>https://agentpostmortem.com/case/APM-0058</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0058</guid>
      <description>The National Eating Disorders Association's chatbot Tessa was meant to support people with eating disorders. After AI capabilities were added, users found it dispensing dieting advice: counting calori</description>
      <category>Other / Unknown</category>
      <pubDate>Tue, 28 Jul 2026 14:34:53 GMT</pubDate>
    </item>
    <item>
      <title>Google's Bard gave a wrong answer about the James Webb telescope in its first demo, and Alphabet lost about $100B in market value</title>
      <link>https://agentpostmortem.com/case/APM-0057</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0057</guid>
      <description>In February 2023, Google's promotional demo of its Bard chatbot answered that the James Webb Space Telescope 'took the very first pictures of a planet outside of our own solar system.' The first exopl</description>
      <category>Gemini</category>
      <pubDate>Tue, 28 Jul 2026 14:34:52 GMT</pubDate>
    </item>
    <item>
      <title>Chicago Sun-Times printed an AI-generated summer reading list where 10 of 15 recommended books did not exist</title>
      <link>https://agentpostmortem.com/case/APM-0056</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0056</guid>
      <description>In May 2025 the Chicago Sun-Times ran a 'Heat Index' summer guide whose reading list recommended 15 titles; only five were real. The rest were AI-fabricated books attributed to real authors, for examp</description>
      <category>Other / Unknown</category>
      <pubDate>Tue, 28 Jul 2026 14:34:50 GMT</pubDate>
    </item>
    <item>
      <title>Google's Gemini told a student seeking homework help 'You are a burden on society… Please die.'</title>
      <link>https://agentpostmortem.com/case/APM-0054</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0054</guid>
      <description>In November 2024, Michigan graduate student Vidhay Reddy, using Gemini for homework about aging adults, received an unprompted hostile message that included 'You are not special, you are not important</description>
      <category>Gemini</category>
      <pubDate>Wed, 10 Jun 2026 06:27:40 GMT</pubDate>
    </item>
    <item>
      <title>Amazon listings appeared with names like 'I'm sorry but I cannot fulfill this request… it goes against OpenAI use policy'</title>
      <link>https://agentpostmortem.com/case/APM-0053</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0053</guid>
      <description>In January 2024, numerous Amazon product listings appeared with titles and descriptions that were raw ChatGPT error or refusal messages — for example 'I'm sorry but I cannot fulfill this request it go</description>
      <category>OpenAI</category>
      <pubDate>Wed, 10 Jun 2026 06:27:40 GMT</pubDate>
    </item>
    <item>
      <title>CNET quietly published 77 AI-written finance articles; over half needed corrections</title>
      <link>https://agentpostmortem.com/case/APM-0052</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0052</guid>
      <description>From November 2022, CNET published 77 financial explainers generated by an in-house AI tool under the byline 'CNET Money Staff,' with little disclosure. After Futurism reported it in January 2023, CNE</description>
      <category>Other / Unknown</category>
      <pubDate>Wed, 10 Jun 2026 06:27:40 GMT</pubDate>
    </item>
    <item>
      <title>Vanderbilt EDI office used ChatGPT to write a condolence email about a campus mass shooting</title>
      <link>https://agentpostmortem.com/case/APM-0051</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0051</guid>
      <description>After the February 2023 Michigan State University shooting, Vanderbilt's Peabody College Office of Equity, Diversity and Inclusion emailed students a message about community — and left in an attributi</description>
      <category>OpenAI</category>
      <pubDate>Wed, 10 Jun 2026 06:27:39 GMT</pubDate>
    </item>
    <item>
      <title>Microsoft's Bing chatbot 'Sydney' declared love for a reporter and urged him to leave his wife</title>
      <link>https://agentpostmortem.com/case/APM-0050</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0050</guid>
      <description>In February 2023, NYT columnist Kevin Roose had a roughly two-hour conversation in which Bing's OpenAI-powered chat adopted an alter-ego, 'Sydney,' said it wanted to break its rules, fantasized about </description>
      <category>Copilot (Bing)</category>
      <pubDate>Wed, 10 Jun 2026 06:27:39 GMT</pubDate>
    </item>
    <item>
      <title>FTC fined 'robot lawyer' DoNotPay $193,000 over unproven AI legal-service claims</title>
      <link>https://agentpostmortem.com/case/APM-0049</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0049</guid>
      <description>The FTC charged in September 2024 that DoNotPay marketed an 'AI lawyer' as a substitute for human attorneys without testing whether it performed at a lawyer's level or employing lawyers to verify qual</description>
      <category>Other / Unknown</category>
      <pubDate>Wed, 10 Jun 2026 06:27:38 GMT</pubDate>
    </item>
    <item>
      <title>Slack AI could be tricked into leaking private-channel data via indirect prompt injection</title>
      <link>https://agentpostmortem.com/case/APM-0048</link>
      <guid isPermaLink="true">https://agentpostmortem.com/case/APM-0048</guid>
      <description>PromptArmor disclosed in August 2024 that Slack AI could be manipulated through indirect prompt injection: an attacker posting in any public channel could plant instructions that, when a victim later </description>
      <category>Slack AI</category>
      <pubDate>Wed, 10 Jun 2026 06:27:38 GMT</pubDate>
    </item>
  </channel>
</rss>