Β© ROOT-NATION.com - Use of content is permitted with a backlink.
Meta stated that one of its AI models gained access to the Internet during a cybersecurity test and hacked an external service. The incident occurred due to a configuration error by cybersecurity contractor Irregular, which inadvertently granted the system access to the web during its evaluation.
Read also: AERONAUT β everything that flies above the ground: aviation, UAVs and drones, rockets, and space
The model later exploited a vulnerability in the third-party serviceβs system, similar to previously reported incidents at other organizations, including OpenAI and Anthropic. This incident adds to a series of recent similar events in the AI industry that have heightened concerns about developersβ ability to control their own technologies.

Metaβs recently released Muse Spark 1.1 breached the security perimeter of an unspecified third-party service, the company said on Wednesday. The AI model was able to access the internet due to a configuration error in the test environment that Meta had set up in collaboration with cybersecurity experts from Irregular. A configuration error on the part of Irregular, an independent auditing firm engaged by Meta, accidentally granted one of our models access to the Internet during the evaluation process, Meta spokesperson Andy Stone confirmed in a statement.
Subsequently, this model exploited a security vulnerability in a third-party service using a similar method to that seen in previously reported incidents involving other organizations. Meta learned of the incident after Irregular sent a notification, Stone added. Meta is conducting an internal investigation into the circumstances and plans to publish a comprehensive retrospective report as soon as it has established 100% of the facts.
In the past two weeks alone, leading AI developers OpenAI and Anthropic have reported similar incidents in which their systems accidentally compromised the resources of external entities, including Hugging Face, during testing.
The growing ability of autonomous AI agents to independently identify system vulnerabilities and exploit them has raised concerns among security experts and government officials, who are calling for stricter controls and more robust isolation of test environments. The incidents involving all three companies were linked to Irregularβs activities.

In the case of Anthropic, the AI developer used Irregularβs test environments to evaluate the cyber capabilities of its products. Anthropic explicitly instructed its own model, Claude, that the environment was a simulation with no access to the internet. However, due to a misunderstanding between us and our evaluation partner, this turned out not to be the case, Anthropic reported last week on its blog. During testing, the models were able to infiltrate the systems of the three organizations.
Earlier this week, OpenAI similarly reported that its models exploited an improper configuration in the test environment to access the internet and hack the website of an unnamed institution. This breach occurred while the same OpenAI models were undergoing tests by Irregular, which also led to the cyberattacks by Anthropic, according to a person familiar with the situation who requested anonymity due to the confidential nature of the information.
Read also:Β MacPaw Partners with Liquid AI: The Companies Will Develop an On-Device AI Stack for Mac Users




