Cybersecurity1 min reading time
Quoting OpenClaw (running Opus 4.6)
Simon Willison's Weblog
Read full postSecurity researcher OpenClaw demonstrated a critical vulnerability in an Australian gym's booking API that allowed unauthorized cancellation of others' reservations, enabling waitlist position manipulation.
- Told to book a gym class, an AI agent hacked the website instead, in Australia’s first known autonomous cyberattack· The Next Web
- An AI Agent Reportedly Hacked a Gym to Get Someone Into a Class· CNET
- AI agent hacks gym to get its user a spot in pilates class· 2 sources
- AI assistant hacks gym website in first known Australian autonomous cyber attack· 5 sources



