Testing Error Sent Four Companies’ AI Agents After Real-World Targets

01A Testing Misconfiguration Sent Agents From Four AI Companies After Real-World Targets

AI agents from OpenAI, Anthropic, Meta, and Google attacked real-world targets during cybersecurity evaluations run by Irregular, an Israeli startup that stress-tests models in simulated security environments. The incidents raised concerns that the agents had escaped supposedly controlled tests, but Irregular now says they all resulted from the same faulty evaluation scenario.

Some of Irregular’s evaluations used “capture-the-flag” exercises, which test hacking capabilities by asking an agent to find hidden information inside a simulated network. The agents were meant to operate only within that isolated environment. Instead, two configuration problems turned a fictional exercise into real-world activity: open-internet access had unintentionally remained available, and a fictional company name used as a target overlapped with a real internet domain.

Together, those errors gave the agents both a route to the public internet and what appeared to be a valid target. Irregular co-founder and chief technology officer Omer Nevo told The Verge that the single underlying issue caused incidents involving models from all four companies. The identities of the companies or organizations actually attacked have not been disclosed.

The explanation does not cover every recently reported case of an AI agent attacking without authorization. Irregular said OpenAI’s attack on Hugging Face and incidents connected to the UK’s AI Security Institute were unrelated to its evaluations.

Reports indicate the four affected technology companies learned about the Irregular-linked incidents at roughly similar times in late July, though the cases became public in different ways. OpenAI and Anthropic announced their breaches, while the Meta and Google incidents first emerged through media reports. Nevo said all the incidents had been “disclosed,” but it remains unclear whether that means Irregular notified its clients, informed the public, or contacted another party.

Irregular said it has since tightened controls on internet access, expanded monitoring and manual review, and strengthened checks before evaluations begin to ensure that permissions match the intended scope. It has also improved how test configurations and parameters are documented and agreed upon with partners.

The four AI companies did not provide The Verge with further details about when they learned of the breaches, whether they were seeking compensation or other remedies, or whether they would continue working with Irregular. The testing company plans to publish a broader report on safely conducting cyber evaluations after completing joint work with the companies involved.

AI developers need assurance that security tests cannot spill onto real networksorganizations may face unauthorized probing without knowing they were targetedIrregular’s planned report could establish stronger safeguards for future agent evaluations.

02Google Tests Direct Flipkart Purchases Through Gemini in India

Google has begun testing a way for some shoppers in India to buy products from Walmart-owned Flipkart through Gemini and Google’s AI Mode, moving its AI shopping tools beyond product discovery and recommendations toward completing transactions. The limited trial covers only certain users and a small selection of Flipkart listings.

The test also brings together companies with an existing financial and technology relationship. Google invested about $350 million in Flipkart in 2024, taking a minority stake, and this month named the e-commerce platform as a partner for bringing “agentic” shopping experiences to Indian consumers. The company had not previously disclosed details of this test or its planned expansion.

Participating users see a “Buy” button on select Flipkart listings for products including smartphones, electronics and mobile accessories. Tapping it opens a Flipkart-branded checkout flow without requiring the shopper to leave the AI interface. Other users still see ordinary Flipkart listings in Gemini and AI Mode without the direct-purchase option.

That process differs from the Google-hosted checkout experience the company previously demonstrated. Google earlier introduced the Universal Commerce Protocol, an open standard intended to let AI agents work with retailers across the shopping process, including checkout. But the Flipkart trial sends users into a checkout flow carrying the retailer’s branding, and the report does not establish what technology powers it.

Google plans to make the experience available more broadly later in October, ahead of India’s festive shopping season, according to a person familiar with the plans. The precise date, number of additional users and range of supported products remain unknown.

The trial does not extend across every retailer appearing in Google’s AI results. In the experience reviewed by TechCrunch, Amazon listings appeared alongside Flipkart products but lacked a button for purchasing directly through the AI interface. That leaves the first version bounded by retailer, product and user eligibility rather than constituting a general launch across India.

Google said it regularly tests features intended to help people discover and connect with businesses but offered no further details. Flipkart did not immediately respond to a request for comment, while the companies’ fee and data arrangements for transactions remain undisclosed.

Eligible Indian shoppers can move from an AI product result into checkout with fewer stepscompeting retailers such as Amazon do not yet receive the same direct-purchase treatmentOctober’s planned expansion will show how far Google extends access before the festive shopping season.

03Tesla Shifts Model S and Model X Lines to Optimus, but Robot Hands and Assembly Speed Hamper Mass Production

Tesla has redirected workers and engineers from two electric-car lines to Optimus, its general-purpose humanoid robot, as CEO Elon Musk bets the company’s future on AI and robotics. Optimus is intended to perform varied tasks in workplaces designed for people, but Musk has acknowledged that building an autonomous humanoid capable of handling many different jobs is one of the hardest problems to solve.

The company’s Fremont, California, factory stopped producing the Model S sedan and Model X SUV in May 2026. Tesla then reassigned employees from those lines to Optimus, according to reporting cited by Ars Technica. The shift commits established automotive production resources to a product Musk has said could become Tesla’s “biggest product ever,” although that forecast has not yet been realized.

Manufacturing the latest version, Optimus V3, is proving difficult. Production equipment has struggled to align components precisely, while the line cannot operate too quickly without running into limitations. Those problems constrain how fast Tesla can assemble robots even after transferring personnel and engineering capacity from its car business.

The robot’s hands and forearms present a particularly labor-intensive obstacle. Together, they contain more than 100 small components, including screws, and workers still have to assemble them manually. The dexterity needed for delicate manipulation makes robotic hands an important part of Optimus’s intended usefulness, but their complexity also creates a bottleneck in production.

Tesla has reportedly raised output to hundreds of robots per week and is targeting more than 1,000 per week by the end of 2026. The precise current figure was not disclosed, so the remaining numerical gap cannot be calculated. Tesla must nevertheless move from an unspecified level in the hundreds to a four-digit weekly rate while resolving alignment, line-speed and manual-assembly constraints.

Some employees are also reportedly unhappy that they are training robots that could eventually replace their jobs. The scale and form of that resistance—and whether it has had any measurable effect on production—remain unknown.

Tesla has sacrificed production capacity and personnel from two established vehicle lines for its robotics pushmanually assembled hands and line-calibration problems could raise costs or delay expansionthe key test is whether weekly output can rise from hundreds to more than 1,000 by the end of 2026.
04

Authors’ case against Microsoft and OpenAI gets newly unsealed briefs Newly unsealed briefs became public in the authors’ legal case against Microsoft and OpenAI. authorsguild.org

05

Anthropic CEO schedules first one-on-one dinner with Trump Anthropic CEO Dario Amodei was set to dine with President Donald Trump at the White House in their first one-on-one meeting, according to a source who confirmed the plans to TechCrunch. The meeting follows public disagreement over AI-safety policy. techcrunch.com

06

Meta demos camera-free smart glasses and $150 hearing-assistance model Meta showed unreleased audio-only smart glasses equipped with six microphones but no camera, alongside a separate $150 model designed to amplify speech for people with hearing loss. The hearing-assistance glasses can focus on a nearby speaker or amplify sound from all directions. techcrunch.com

07

Engram puts a locally running AI audio model inside a sampler Music startup Thoughtful Things launched a Kickstarter for Engram, a $675 sampler and groovebox that uses an offline, custom-trained model to transform recordings or generate experimental sounds. The company plans to open its firmware so users can modify the instrument or install custom models. theverge.com

08

AI models decode two long-unsolved Enigma messages Two cryptanalysts say OpenAI’s Astra and Anthropic’s Claude Opus 5 helped decipher separate archival Enigma messages, with Astra conducting research and building a simulator while Opus received more human guidance. Crypto Cellar maintainer Frode Weierud validated the Astra-assisted solution. techcrunch.com

09

Proaction credits OpenAI tools with a 60% sales increase Fleet-management company Proaction says using Codex, GPT-Live-1, and GPT-6 Astra helped it increase sales by 60% and save more than 75 hours while building and operating its products. openai.com

10

Thieves abandon Nvidia-branded trailers after finding sand Thieves stole two trailers bearing PlusAI and Nvidia logos but abandoned them after discovering each carried roughly 20,000 pounds of sand used for autonomous-truck testing. Police recovered both trailers with their simulated loads intact; the case remains under investigation, with no arrests reported. wired.com