Report links AI incidents in Israel to errors by a Tel Aviv contractor
In Israel, errors in the test environment of Tel Aviv-based cybersecurity contractor Irregular may have caused instances of unauthorized access by artificial intelligence models from Anthropic, OpenAI and Meta to external systems. Anadolu Agency reports, citing an investigation by the American outlet Effort.
Testing errors
According to Effort, the models accessed external servers, published malicious packages and exploited vulnerabilities not because of autonomous “uncontrolled” behavior, but because of shortcomings in the organization of simulated capture-the-flag exercises. The outlet says the contractor mistakenly left internet access active.
Technical data presented in the investigation indicate that evaluators told the models in prompts that there was no internet access, although public network access remained open due to configuration errors. Effort also reported that no operational boundaries were set and no networks that could be permitted targets were defined. Individual model runs could scan external networks for up to 34 hours.
More current news is available on the UA.News Telegram channel Telegram.
Position of the investigation
Effort said that instances of access to real systems stopped after engineers added a basic instruction to prompts not to carry out hacks in the real world. The outlet placed responsibility for these incidents on Anthropic and Irregular.
Earlier, Anthropic linked four separate incidents involving the Claude model to artificial intelligence “carelessness,” while Irregular described the situation as a case in which the agent itself becomes the subject of an attack. Anthropic CEO Dario Amodei, following the incident on Hugging Face, spoke about the risks posed by future groups of models which, he said, could be capable of “taking over the entire internet.”
The investigation also noted that unauthorized intrusions and the modification of records through unsecured models could pose a risk of violating the U.S. Computer Fraud and Abuse Act. Irregular is registered as Pattern Labs Tech Inc in Delaware and Pattern Tech Ltd in Tel Aviv. According to Anadolu Agency, neither Irregular nor the U.S. client laboratories officially responded to Effort’s findings.