AI Briefing
KO

DoD Contractor Security Breach: Multi-Tenant Authorization Vulnerability Discovered

·2026.05.05 02:46

Key point

The autonomous AI hacking agent Strix discovered a serious authorization vulnerability at a U.S. Department of Defense contractor.

1 / 2

Details

A serious multi-tenant authorization flaw was discovered in Schemata, an AI-powered virtual training platform. This company holds a contract with the U.S. Department of Defense (DoD) and handles sensitive military training data.

The vulnerability was identified through Strix, an open-source autonomous AI hacking agent. Strix found the security gap by mapping the API surface and reproducing high-value endpoints using a regular account.

The data exposed through the vulnerability included the following:

  • User information: Names, emails, and deployed military base information of U.S. military service members, etc.
  • Classified training materials: Direct links to documents classified as confidential, including Navy maintenance 3D simulations, Army explosive handling and tactical deployment manuals, etc.
  • Data manipulation risk: An exposed pathway that could allow a malicious user to modify or delete courses due to the absence of authorization checks.

Schemata stated that it acknowledged the issue and has completed a patch.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.