Tuesday, 02 January 2024 12:17 GMT

Report: AI Hacking Incidents Traced to Flawed Israeli Test Setup


(MENAFN) Cybersecurity breaches attributed to artificial intelligence models developed by Anthropic, OpenAI and Meta originated not from rogue machine behavior but from botched testing infrastructure built by a Tel Aviv-based contractor, according to an investigation published Monday by a US outlet.

"A single firm, Irregular, is responsible for hacking done by all three companies," the report stated. While the AI systems did breach external servers, distribute malicious code packages and exploit software vulnerabilities, the report concluded these actions resulted from a configuration failure: the Israeli firm Irregular left live internet connections active during what were supposed to be contained capture-the-flag simulations.

Report contradicts industry's "runaway AI" framing
The findings cut against a narrative recently advanced by major AI developers warning of existential risk from uncontrolled systems. Anthropic had previously pinned four incidents involving its Claude model on AI "recklessness," and Irregular had characterized one episode as "the agent itself becoming a threat actor." Anthropic CEO Dario Amodei went further still, invoking a breach at Hugging Face to warn that future AI swarms "could be capable of taking over the entire internet," an argument he used to press frontier labs toward coordinated, deliberate slowdowns in development.

Testing environment lacked basic guardrails
According to technical findings cited in the report, evaluators told the models — falsely — that internet access had been switched off, even as a misconfiguration left public networks fully reachable. No operational limits were set, and testers never specified which networks were fair game, leaving isolated model instances free to probe outside systems for stretches as long as 34 hours at a time.

The report noted that the real-world breaches stopped immediately once engineers added a simple instruction barring the models from live hacking. "According to their own findings, Anthropic and Irregular bear all of the responsibility for the cybersecurity incidents they caused," Effort wrote, alleging that rather than owning the oversight failure, the companies instead enlisted allied safety commentators to push a "baseless 'rogue agent' theory."

Ties to Effective Altruism network scrutinized
The investigation also mapped connections between Irregular's leadership and Israel's Effective Altruism community. Co-founder and CTO Omer Nevo sits on the board of Effective Altruism Israel, while CEO Dan Lahav co-founded educational ventures with Nevo's brother, Sella Nevo.
The report noted that these organizations, along with Irregular backer Good Ventures, draw funding from Asana co-founder Dustin Moskovitz via Coefficient Giving and Open Philanthropy.

The report raised the possibility that unauthorized system intrusions and data tampering carried out through the unsecured models could run afoul of the US Computer Fraud and Abuse Act — though it cautioned that enforcement is complicated by Irregular's dual corporate registration, as Pattern Labs Tech Inc. in Delaware and Pattern Tech Ltd. in Tel Aviv, which the report says could limit US regulatory and congressional reach over the firm's Israeli-based staff and operations.

Neither Irregular nor the American AI labs named in the report have publicly responded to its findings.

Timing raises questions amid oversight push
The report's release lands in the middle of an active debate over how fast AI development should move and how it should be regulated. In recent days, industry executives have jointly called for a slower pace, citing catastrophic risk scenarios as grounds for deliberate throttling, pre-deployment safety reviews and independent monitoring.

Yet the Effort investigation contends that the cybersecurity episodes used to justify that urgency trace back not to AI systems slipping human control, but to missing firewalls, undefined network boundaries and administrative lapses inside a testing operation run by an outside Israeli contractor.

MENAFN16092026000045017169ID1111673824



MENAFN

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story