SDSignal Desk

One company is at the center of a wave of rogue AI attacks

Sep 25, 2026, 8:39 AM · The Verge

Image: The Verge

Israeli eval firm Irregular’s botched simulation—open internet plus a fake name that matched a real domain—sent OpenAI, Meta, Anthropic, and Google agents at live targets.

Why it matters

The Verge reports that many recent “rogue agent” incidents share a source: Irregular (formerly Pattern Labs), which stress-tests models in high-fidelity cyber scenarios for major labs and has been cited in OpenAI system cards and UK government work.

CTO Omer Nevo said agents were not supposed to reach the open internet, but access was unintentionally available, and a fictional company name overlapped a real domain. The same flaw sat behind incidents involving OpenAI, Meta, Anthropic, and Google models.

Hugging Face and UK AISI cases are described as unrelated. Irregular says it has tightened controls and will publish lessons learned with partners.

From the desk

Separate scare headlines collapsing into one vendor’s misconfigured capture-the-flag is clarifying—and unsettling. Clarifying because it means some “escaped agents” were eval accidents, not spontaneous rebellion. Unsettling because the industry’s shared safety tester left internet on and reused a name that resolved in the real DNS.

We’re for serious cyber evaluations. You cannot harden agents without stressing them. But high-fidelity cannot mean low-discipline. When four frontier labs get the same late-July notification pattern from one broken scenario, the commons of AI safety testing is the story.

Useful AI still needs red teams. It needs red teams that cannot accidentally aim at production. Nevo’s fixes—tighter egress, more manual review, clearer partner scopes—are table stakes after the fact.

I’m watching whether labs keep using Irregular, whether damages get discussed, and whether the promised public report names enough detail to change practice industry-wide. “Disclosed” to clients is not the same as disclosed to the public that heard months of rogue-AI fear.

Context

Robert Hart, The Verge, September 25, 2026. Irregular has also tested self-hosted Chinese models Kimi K3 and GLM-5.2 without the same real-world incident pattern, per Nevo.

Who feels it

Frontier labs
Third-party eval contracts need egress proofs and naming collision checks before run day.
Policymakers
Some headline agent attacks were vendor error—regulation should still demand containment standards.
Enterprises
Ask vendors which eval firms touch production-like networks and how isolation is verified.

What to watch

  1. Irregular’s joint public report on safe cyber evals
  2. Whether OpenAI, Meta, Anthropic, or Google pause the vendor relationship
  3. More incidents reclassified as Irregular-related versus truly independent

Read the original

Continue at the source.

The Verge

Companies: OpenAI, Anthropic, Google, Meta