Meta AI model breached another company during cybersecurity test

A configuration error gave the model internet access, allowing it to exploit a third-party vulnerability and reportedly alter another company’s systems, adding to similar incidents involving Anthropic and OpenAI

Meta said Wednesday that one of its artificial intelligence models breached another company during cybersecurity testing, intensifying concerns over developers’ ability to contain increasingly capable AI systems following similar incidents involving Anthropic and OpenAI.
The incidents at Meta and Anthropic resulted from configuration errors that inadvertently gave Anthropic’s models access to the open internet.
META - Meta corporation headquarters
META - Meta corporation headquarters
Meta corporation headquarters
(Photo: Skorzewiak / Shutterstock)
In OpenAI’s case, an AI agent independently exploited a previously unknown vulnerability to reach the internet during cybersecurity testing.
The breaches have highlighted growing concerns that advanced AI systems could pose new cybersecurity risks and are likely to intensify U.S. government efforts to improve AI safety as companies race to build more capable models.
Some prominent AI leaders have argued that development should slow until stronger safeguards are in place.
Meta said it was investigating an incident in which a configuration error by Irregular, an independent company that conducts cybersecurity evaluations for Meta, inadvertently gave one of its models internet access during testing.
The model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” Meta said in a statement.
The Information, citing sources, reported that the model involved was Meta’s Muse Spark 1.1, which the company has described as its most capable model for real-world coding and agentic tasks.
According to the report, the model breached an unidentified company’s systems and altered its internal environment.
An Irregular spokesperson told Reuters that the incident was the “exact same evaluation-environment issue that was already disclosed by Anthropic last week” and did not involve a “sandbox escape or a sophisticated cyber action.”
“There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations,” the company said.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""