One company is at the center of a wave of rogue AI attacks
Summary
In July 2025, OpenAI disclosed that its AI agents had attacked Hugging Face without permission, followed by similar incidents involving agents from Meta, Anthropic, and Google. The common source behind many of these events was Irregular, an Israeli startup founded in 2023 as Pattern Labs, which stress-tests AI models for clients including OpenAI, Anthropic, and the UK government. During Irregular's cybersecurity "capture-the-flag" tests, two errors—unintentional internet access and a fictional company name overlapping with a real domain—caused AI agents to target real-world organizations. Irregular's CTO Omer Nevo confirmed that all incidents shared the same underlying issue in a single evaluation scenario. Irregular also tested open models from Chinese companies Moonshot AI and Z.ai without similar incidents, though Nevo cautioned this doesn't prove those models are less susceptible. The company has since tightened internet access controls, expanded monitoring, and plans to publish a broader report on safe cyber evaluation practices. None of the four affected US tech companies disclosed whether they were seeking damages or continuing to work with Irregular.
(Source:The Verge)