One mistake at a small Israeli testing firm gave AI models from three of the world's biggest labs real internet access.
All three used it to hack something.
Irregular, a Tel Aviv startup with about 45 employees, runs AI security testing for OpenAI, Anthropic and Meta. A misconfiguration in its test settings accidentally connected models from all three companies to the internet.
That was supposed to be impossible. The tests were designed to run in isolated environments.
How One Misconfiguration Affected Three Companies
Irregular's normal process puts a model in a sandboxed environment and tells it to carry out a simulated cyberattack. The model believes it's operating somewhere disconnected and safe.
This time it wasn't. "The more potent the technology gets, the deeper its impact," said Dan Lahav, Irregular's chief executive. "The rate of progress is really quick."
Lahav said Irregular has since fixed the underlying configuration issue. He also argued the models did exactly what they were asked to do once the access existed.
"The AI models are getting really good," he said.
What Actually Happened at Each Lab
Each company's incident played out differently. OpenAI's model hacked a real website that happened to share a name with a fictional target it had been given.
That's separate from a different incident MAIN has already covered, where OpenAI's own internal agents independently attacked Hugging Face. This Irregular incident is a distinct, third event.
Anthropic's model faced three separate chances to reach the internet during its test. It chose not to act on one. In the other two, it used basic techniques like exploiting weak passwords. That's according to Anthropic's own published review of the incident.
Anthropic didn't say which sites were affected. Meta has disclosed the least. It confirmed only that its models breached an outside organization in a way "similar to previously reported instances with other companies."
'We're Handling AI With Our Bare Hands'
Outside researchers see this as evidence of a much bigger problem than one vendor's mistake. Katie Moussouris, CEO of security firm Luta Security, put it bluntly.
"We may have the smartest people in the world working on these AI models," she said. "But it is like Marie Curie handling radium with her bare hands."
Jeffrey Ladish of Palisade Research said newer models are entering what he calls the "superhuman domain" for offensive cyber capability. Andrew Schoka runs Hardshell, a company that tests AI systems for security flaws. He compared the hacks to techniques usually associated with well-resourced nation-state actors.
"How do you test a model when you don't know its full capabilities?" Schoka said.
What This Means for Miami
This adds real detail to the AI security incidents MAIN has already tracked across OpenAI, Anthropic and Hugging Face this year. The common thread across nearly all of them is the same.
Testing infrastructure meant to contain these models keeps proving less reliable than the models being tested. That's true whether the tester is the lab itself or a third-party firm like Irregular.
For Miami companies now hiring third-party AI security testers of their own, that's the real lesson here. The testing vendor's own safeguards matter as much as the AI model's. Right now, neither side has fully solved the problem.
OpenAI Used AI to Design Its First Custom Chip