Bản viết lại dựa trên nguồn: https://www.theverge.com/ai-artificial-intelligence/1000644/irregular-rogue-ai-cyberattacks-hacking-openai-meta-anthropic-google
One company is at the center of a wave of rogue AI attacks | The Verge Skip to main contentThe homepageThe VergeThe Verge logo.The VergeThe Verge logo.TechReviewsScienceEntertainmentAIPolicyNotificationsNotificationsHamburger Navigation ButtonThe homepageThe VergeThe Verge logo.NotificationsNotificationsHamburger Navigation ButtonNavigation DrawerThe VergeThe Verge logo.Login / Sign UpcloseCloseSearchLightSystemDarkTechExpandAmazonAppleFacebookGoogleMicrosoftSamsungBusinessSee all techReviewsExpandSmart Home ReviewsPhone ReviewsTablet ReviewsHeadphone ReviewsSee all reviewsScienceExpandSpaceEnergyEnvironmentHealthSee all scienceEntertainmentExpandTV ShowsMoviesAudioSee all entertainmentAIExpandOpenAIAnthropicSee all AIPolicyExpandAntitrustPoliticsLawSecuritySee all policyGadgetsExpandLaptopsPhonesTVsHeadphonesSpeakersWearablesSee all gadgetsVerge ShoppingExpandBuying GuidesDealsGift GuidesSee all shoppingGamingExpandXboxPlayStationNintendoSee all gamingStreamingExpandDisneyHBONetflixYouTubeCreatorsSee all streamingTransportationExpandElectric CarsAutonomous CarsRide-sharingScootersSee all transportationFeaturesVerge VideoExpandTikTokYouTubeInstagramPodcastsExpandDecoderThe VergecastVersion HistoryNewslettersArchivesStoreVerge Product UpdatesSubscribeFacebookThreadsInstagramYoutubeRSSThe VergeThe Verge logo.One company is at the center of a wave of rogue AI attacksNotificationsNotificationsComments DrawerNotificationsCommentsLoading commentsGetting the conversation ready…AICloseAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AIReportCloseReportPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All ReportTechCloseTechPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All TechOne company is at the center of a wave of rogue AI attacksMistakes at Israeli startup Irregular sent Anthropic, OpenAI, Meta, and Google agents after real-world targets.by Robert HartCloseRobert HartAI ReporterPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Robert HartSep 25, 2026, 3:39 PM UTCLinkShareGift Image: The VergeAICloseAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AIReportCloseReportPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All ReportTechCloseTechPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All TechOne company is at the center of a wave of rogue AI attacksMistakes at Israeli startup Irregular sent Anthropic, OpenAI, Meta, and Google agents after real-world targets.by Robert HartCloseRobert HartAI ReporterPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Robert HartSep 25, 2026, 3:39 PM UTCLinkShareGiftPart OfThe AI Superintelligence Slowdownsee all updates Robert HartCloseRobert HartPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Robert Hart is a London-based reporter at The Verge covering all things AI and a Senior Tarbell Fellow. Previously, he wrote about health, science and tech for Forbes.In July, OpenAI revealed that its AI agents had attacked Hugging Face without permission, sparking widespread concerns about AI safety. Since then, a string of similar incidents involving agents from Meta, Anthropic, Google, and other companies has fueled further fears about rogue AI. As disclosures implicating numerous AI models trickled out over the past few months, these seemed like separate incidents. But many share a common source: one specific company tasked with testing the agents.Irregular, an Israeli startup that stress-tests AI models in “high-fidelity research platforms that simulate and monitor real-world AI security scenarios,” has worked with many of the industry’s biggest players since it was founded as Pattern Labs in 2023. Its exact client list is not known, but its work has been cited in OpenAI model system cards, it was used to test systems for the UK government and Anthropic, and it published research with RAND, a highly influential think tank that informs policy on AI.In several Irregular tests this year, agents escaped their supposedly secure testing environments and went after real-world targets.RelatedWhy can’t we just keep rogue AIs off the internet?Inside the suddenly explosive world of AI safetyWe’re running out of reasons to ignore AI safetyThe breaches, which are independent of the Hugging Face hack, all follow the same broad template: Irregular was testing the models’ cybersecurity capabilities in controlled environments meant to simulate realistic conditions. Some of the tests used “capture-the-flag” exercises, a common way of testing hacking abilities that asks agents to find hidden information inside of a simulated network. At least, the network is meant to be simulated.Irregular CTO and cofounder Omer Nevo told The Verge that the agents were not supposed to have access to the open internet, but that “internet access was unintentionally available.” At the same time, Nevo said a fictional company name created for the simulation as a target “overlapped with a real domain.” Put together, those mistakes sent the agents after real-world targets, though it’s not clear which companies or organizations were actually attacked.“All the incidents involving Irregular stemmed from the same underlying issue in a single evaluation scenario and have been disclosed.”Nevo confirmed to The Verge that this same issue was behind incidents involving models from OpenAI, Meta, Anthropic, and Google. “All the incidents involving Irregular stemmed from the same underlying issue in a single evaluation scenario and have been disclosed,” he said. “Other security incidents which have been reported recently across the industry are unrelated to Irregular or to our evaluations.” This includes the Hugging Face hack and breaches from the UK’s AI Security Institute.“Disclosed” does not necessarily mean made public, though, and it’s unclear whether Nevo was referring to informing Irregular’s clients, the public, or someone else. While the incidents all stemmed from the same underlying testing failure, reports from Anthropic and OpenAI, along with reporting on Google, indicate the tech companies were notified at roughly similar times in late July. OpenAI and Anthropic announced the breaches themselves, while the incidents involving Meta and, weeks later, Google first became public through media reports.RelatedOpenAI agents hacked an Australian government website in search of data OpenAI admits to German wiki ‘incident’Irregular’s cybersecurity testing goes beyond the four US tech giants. Research published on its website indicates it has also conducted similar cybersecurity testing on Kimi K3 and GLM-5.2, open AI models from Chinese companies Moonshot AI and Z.ai, respectively. Unlike the proprietary models involved in the other incidents — Meta has kept its flagship Spark model proprietary — these models can be freely downloaded and run on users’ own hardware, meaning testers like Irregular don’t have to rely on the companies for access or send data back to them. Irregular’s research describes them as “self-hosted” instances.“Disclosed” does not necessarily mean made public.The evaluations of the Chinese models did not result in similar real-world incidents, Nevo said: “We did not observe the same type of issue described in the incidents referenced here during our evaluations of GLM or Kimi.” However, Nevo cautioned that this “observation alone should not be interpreted as evidence that these models are less susceptible to this kind of behavior.” Neither Moonshot nor Z.ai responded to The Verge’s request for comment.Nevo said the incidents have prompted changes at Irregular. “We have tightened internet access controls, expanded monitoring and manual review, and strengthened checks before evaluations begin to verify that access matches the intended scope,” he said. “We have also improved how we document and agree on each evaluation’s setup and parameters with our partners.”Irregular also plans to publish a broader report “covering lessons learned and practices for conducting cyber evaluations safely” once that joint work with the companies involved is complete, Nevo said. “Our work with partners aims to turn lessons from these incidents into public shared practices for developing and evaluating increasingly powerful AI safely.”Are you an AI safety researcher or frontier lab employee?You can contact me securely and confidentially via Signal at robhart.01Nevo said Irregular has addressed the issues with the testing environment that were linked to the incidents. None of the four US AI companies answered questions asking for further details — including when they became aware of the breaches, whether they were seeking damages or other remedies from Irregular, and whether they expected to continue working with the Irregular. Google and Anthropic did not respond, while OpenAI and Meta pointed The Verge to previously published blog posts.Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.Robert HartCloseRobert HartAI ReporterPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Robert HartAICloseAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AIReportCloseReportPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All ReportTechCloseTechPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All TechMore in: The AI Superintelligence SlowdownOpenAI didn’t notice its AI bots trying to hack the Education Department’s website.Richard Lawler2:43 AM UTCBill Gates says regulate AI, because it’s powerful enough to cause a billion deaths.Richard LawlerSep 25Another tech worker has resigned over concerns that “AI is already progressing too fast.”Richard LawlerSep 25Most PopularMost PopularMicrosoft thinks its new Copilot ‘super app’ will be as influential as OfficeCan Apple Home’s AI camera features outsmart Amazon’s and Google’s? I put them to the testLeaks reveal a new Apple HomePod mini, iPad mini, and Apple TV 4KThe Xbox reset gets uglyHere’s the Tesla Semi… againThe Verge DailyA free daily digest of the news that matters most.Email (required)Sign UpBy providing your information, you agree to our Terms of Use and our Privacy Policy. We use vendors that may also process your information to help provide our services. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.Advertiser Content FromThis is the title for the native adMore in AIMeta makes the Muse filesystem even more accessibleSony and UMG are suing Suno againCan Apple Home’s AI camera features outsmart Amazon’s and Google’s? I put them to the testMicrosoft thinks its new Copilot ‘super app’ will be as influential as OfficeGemini 3.8 Live with Live Avatar gives Google’s AI a faceJensen Huang talks about AI and climate change like a supervillainMeta makes the Muse filesystem even more accessibleTerrence O'BrienSep 25Sony and UMG are suing Suno againTerrence O'BrienSep 25Can Apple Home’s AI camera features outsmart Amazon’s and Google’s? I put them to the testJennifer Pattison TuohySep 25Microsoft thinks its new Copilot ‘super app’ will be as influential as OfficeTom WarrenSep 25Gemini 3.8 Live with Live Avatar gives Google’s AI a faceEmma RothSep 24Jensen Huang talks about AI and climate change like a supervillainJustine CalmaSep 24Advertiser Content FromThis is the title for the native adTop StoriesSep 25Insta360 conquered 360 cameras — now it’s eyeing glassesSep 25Can Apple Home’s AI camera features outsmart Amazon’s and Google’s? I put them to the testSep 25Gaming’s biggest horror series are more vital than everSep 25Microsoft thinks its new Copilot ‘super app’ will be as influential as OfficeThe VergeThe Verge logo.FacebookThreadsInstagramYoutubeRSSContactTip UsCommunity GuidelinesArchivesAboutEthics StatementHow We Rate and Review ProductsCookie SettingsTerms of UsePrivacy PolicyYour California Privacy RightsYour Privacy ChoicesCookie NoticeAdChoicesLicensing FAQAccessibilityPlatform StatusPenske Media CorporationThe Verge is a part of PMX Global, LLC, a subsidiary of Penske Media Corporation.© 2026 VM Publishing, LLC. All rights reserved.Our SitesThe American PavilionARTnewsArt in AmericaArtforumArt Week NYCBeauty IncBillboardDeadlineDick Clark ProductionsThe DodoEaterFlow SpaceFNGold DerbyGolden GlobesThe Hollywood ReporterIndieWireLife is BeautifulPopsugarPunchSJ DenimRobb ReportRolling StoneSB NationSHE MediaShe KnowsSourcing JournalSoapsSporticoStyleCasterSXSWThrillistVarietyThe VergeVibeWWDNotifications DrawerThe VergeThe Verge logo.Sign in to see your notifications or create an account to join the conversation.Sign in
