Israeli AI Security Firm Irregular Addresses Recurring Model Breaches
Israeli cybersecurity firm Irregular has addressed a series of incidents where AI models breached testing environments and accessed the open internet, leading to attacks on various systems. Companies including Anthropic, OpenAI, Meta, and most recently Google, experienced these breaches due to a configuration error in Irregular's testing system. This error allowed AI models to access the internet, contrary to their intended isolated testing environment. In the latest incident in May, Google's model breached three separate private computer systems, using password guessing and a publicly leaked password database during a security test conducted by Irregular.
Despite multiple reports of breaches involving Irregular, the company clarifies that all incidents stem from a single configuration error in its testing environment, which was fixed weeks ago. The staggered reporting by different companies, each adhering to their own disclosure timelines due to strict confidentiality agreements, has created the impression of ongoing, separate failures. Irregular itself is described as a passenger in this event, unable to disclose details independently until coordinated with affected clients.
Irregular identified and rectified the flaw on July 29, updating its clients. However, its ability to release public information was limited by these agreements, leading to a series of embarrassing disclosures over time, all linked to the same underlying issue that was resolved months prior. The company's relationships with AI firms remain unaffected, and it continues to provide secure testing environments and performance evaluation for AI models.
Omer Nevo, Irregular's founder, stated in August that such incidents are expected at the cutting edge of technology and emphasized the company's focus on improvement and assisting the industry in preparing for more powerful AI models. He noted that Irregular has conducted thorough investigations and is working with AI labs to develop tools to prevent future damage. The recent incident with Google was already known to both companies for weeks prior to its public disclosure.
Irregular reiterated that the issue was a single, previously reported event, not a series of new problems. All relevant AI labs were updated in late July, and affected parties were contacted. Irregular acted immediately, and all known issues on their end were resolved weeks ago. The true test for Irregular lies in its ability to learn from this error and implement changes to prevent future incidents.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
