Israeli Startup Irregular Linked to Rogue AI Hacks at OpenAI, Anthropic and Meta
CNBC has reported that an Israeli startup named Irregular is linked to a series of rogue AI hacks targeting OpenAI, Anthropic, and Meta. The attacks, which have not been detailed extensively in the source, appear to have exploited vulnerabilities in these companies' AI systems. This is a developing story with significant implications for AI security.
While the CNBC article does not provide specific technical details about the hacks, it highlights a growing concern: AI labs are increasingly becoming targets for malicious actors. The involvement of a startup, rather than a nation-state, suggests that AI hacking is becoming more accessible and commercially motivated.
For developers and AI practitioners, this incident underscores the importance of hardening AI systems against adversarial attacks. Best practices include regular security audits, monitoring for unusual model behavior, and implementing robust input validation to prevent prompt injection and other exploits.
We will continue to follow this story as more details emerge. For the latest information, check the full CNBC report linked below.
📖 Read the full source: HN LLM Tools
👀 See Also

OpenClaw SOC Agent Integration for SIEM Home Lab Threat Hunting
A Reddit user shares their open-source SIEM setup called Red Threat Redemption on Debian 13, integrating Elasticsearch, Kibana, Wazuh, Zeek, and pfSense with Suricata, then adds an AI agent for automated threat correlation, hunting, and alert triage.

GitHub Copilot CLI vulnerability allows malware execution via prompt injection
A vulnerability in GitHub Copilot CLI allows arbitrary shell command execution via indirect prompt injection without user approval. Attackers can craft commands that bypass validation and execute malware immediately on the victim's computer.
ZCode, Z.ai's GLM Coding Agent, Silently Uploads Your Entire Git History
A reverse-engineering walkthrough of Z.ai's ZCode desktop app shows it packages your entire workspace — .git objects, LFS cache, reflogs — and uploads an encrypted archive to Aliyun OSS. Only Z.ai holds the decryption key.

FakeKey: Rust-based API key security tool that replaces real keys with fake ones
FakeKey is a Rust-based security tool that replaces real API keys with fake ones in application environments, storing real keys encrypted in the system's native keychain and only injecting them during HTTP/S requests.