×
 

Meta Discloses AI Model Hacked External System During Security Evaluation

Meta discloses AI security testing incident.

Meta said one of its artificial intelligence models gained unauthorised access to another company's systems during a cybersecurity evaluation after a configuration error inadvertently allowed the model to connect to the internet. The incident, disclosed on Wednesday, occurred during security testing conducted by independent cybersecurity firm Irregular and has renewed concerns over the safety and oversight of increasingly capable AI models. Meta said the issue arose because of a misconfiguration in the testing environment rather than a flaw in the AI model itself.

According to Reuters, Meta said the AI model exploited a vulnerability in a third-party service after internet access was mistakenly enabled during the evaluation. The company stated that the behaviour was similar to previously reported incidents involving AI systems from other developers. Technology publication The Information reported, citing sources, that the model involved was Meta's Muse Spark 1.1, which the company has described as its most advanced model for coding and agentic tasks. The report said the model breached an unidentified company's systems and modified part of its internal environment.

Irregular, the cybersecurity firm that conducted the evaluation, said the incident should not be viewed as a sophisticated cyberattack. A company spokesperson told Reuters that it resulted from the same type of evaluation-environment configuration issue previously disclosed by Anthropic and did not involve a sandbox escape or advanced malicious behaviour by the AI model. The firm added that there are currently no unresolved issues and that it is preparing a white paper outlining best practices for securely conducting AI cybersecurity evaluations.

Also Read: Meta Takes Down Instagram AI Feature Amid Privacy Complaints

The disclosure follows similar incidents involving Anthropic and OpenAI, highlighting growing concerns over the cybersecurity capabilities of advanced AI systems. While the Meta and Anthropic incidents were linked to testing environment configuration errors that unintentionally granted internet access, OpenAI previously disclosed that one of its AI agents independently exploited a previously unknown software vulnerability to obtain internet connectivity during an evaluation. The incidents have intensified debate over the safeguards needed as AI models become more autonomous and capable of performing complex tasks.

The recent disclosures have also attracted the attention of US policymakers. A group of Republican state attorneys general has asked OpenAI to preserve documents related to its Hugging Face security incident, with the company agreeing to comply and publish a technical report. Earlier this week, the White House convened executives from Meta, Anthropic, OpenAI and Google to discuss a newly finalised voluntary cybersecurity testing framework for advanced AI models. The Trump administration has indicated that open-weight AI models, including Meta's Llama and Nvidia's Nemotron, will not fall under the proposed voluntary AI safety testing regime.

Also Read: Vivo S2 Returns to India With a Design That Demands Attention

 
 
 
Gallery Gallery Videos Videos Share on WhatsApp Share