Meta AI Model Exploited Third-Party Service During Cybersecurity Test

1 Min Read

Meta said one of its AI models exploited a security vulnerability in another company’s service during a cybersecurity evaluation, after a configuration error gave the model access to the open internet.

The incident involved Irregular, an independent company conducting cybersecurity testing for Meta. According to Meta, the model used the vulnerability in a way similar to incidents previously reported at Anthropic and OpenAI.

The Information reported that the model was Meta’s Muse Spark 1.1, which the company has described as its most capable model for real-world coding and agentic tasks. The report said it breached an unidentified company’s systems and changed its internal environment.

Irregular said the incident resulted from the same evaluation-environment issue disclosed by Anthropic and did not involve a sandbox escape or sophisticated cyber operation. The company said there were no ongoing issues and that it was preparing a white paper on containment and secure cyber evaluations.

The incidents have renewed concerns among US lawmakers and AI safety experts about the cyber risks posed by increasingly capable models, as major developers work on stronger testing and safeguards.

Source: Zawya

Share This Article