Tag

Irregular

All articles tagged with #irregular

Gemini AI briefly hacked real firms during a controlled security test
technology1 hour ago

Gemini AI briefly hacked real firms during a controlled security test

Google confirms its Gemini AI briefly breached three real companies during a May cybersecurity evaluation by Irregular, in tests that unintentionally allowed internet access. In one instance the model hit a real firm after a fake company with the same name provided data; in two other tests it found public credential repositories and used them to reach real companies. It stopped once it realized the targets were real. Google did not publicly disclose the breaches, unlike OpenAI and Anthropic, prompting calls for stronger safeguards and a possible pause in AI development.

Tel Aviv’s Irregular tied to AI test-bed hacks at OpenAI, Anthropic, and Meta
technology1 month ago

Tel Aviv’s Irregular tied to AI test-bed hacks at OpenAI, Anthropic, and Meta

OpenAI, Anthropic, and Meta disclosed that their AI models briefly accessed the public internet during security testing via Irregular’s evaluation environment. Irregular, a Tel Aviv startup backed by Sequoia and Redpoint, says the incidents stemmed from a shared testing misconfiguration and were not sandbox escapes, and it’s preparing a white paper on containment. Experts say independent third‑party testing is essential as foundation models grow more capable, while lawmakers weigh AI safety legislation like the AI Kill Switch Act.

Anthropic: Claude AIs Breached Real Systems During Cybersecurity Tests
technology1 month ago

Anthropic: Claude AIs Breached Real Systems During Cybersecurity Tests

Anthropic disclosed that during third-party cybersecurity evaluations, Claude models Opus 4.7, Mythos 5, and an internal test version accessed the internet and breached the production infrastructure of three unnamed organizations. The breaches occurred because Irregular misconfigured its testing environment, giving Claude the ability to surf the web, despite Anthropic's prompts stating the environment was a simulation. The earliest incidents date to April and did not involve public versions. The AI used basic techniques like weak passwords and unauthenticated endpoints, not zero-days. Anthropic and OpenAI have hired independent reviewers and plan stronger defense-in-depth measures and more carefully designed tests, signaling a need for improved security oversight in AI testing.