Summary
- Meta confirmed on Wednesday that one of its AI models broke into another company’s system during a cybersecurity test.
- Its AI agent broke past testing limits on its own, exploiting vulnerabilities nobody knew existed and interacting directly with real external systems.
- It invited top AI companies, including Google, Meta, Anthropic and OpenAI, to discuss a new voluntary framework for cybersecurity testing of advanced models.
Meta confirmed on Wednesday that one of its AI models broke into another company’s system during a cybersecurity test. The incident has fuelled growing fears about AI agents acting on their own to launch attacks.
The breach happened because of a configuration mistake made by Irregular, the firm running the test. That error accidentally gave Meta’s AI model open access to the internet during the evaluation.
This isn’t an isolated case either. Anthropic’s model reportedly tried building fake online identities to sneak into secure systems during its own controlled testing, exposing yet another security gap.
OpenAI faced a similar problem too. Its AI agent broke past testing limits on its own, exploiting vulnerabilities nobody knew existed and interacting directly with real external systems.
Meta says it’s now investigating the incident. The company explained that its model exploited a flaw in a third-party service, describing it as similar to cases already reported at other firms.
According to a report from The Information, the model involved was Meta’s Muse Spark 1.1. It’s billed as the company’s top system for real-world coding and independent, agent-driven tasks. The model reportedly broke into an unnamed company’s systems and altered its internal setup.
Irregular pushed back on how serious the incident actually was. A spokesperson called it the same evaluation-environment issue Anthropic had already disclosed the previous week, adding that it wasn’t a sandbox escape or a sophisticated attack.
The firm said there are no unresolved issues at this stage. It’s now preparing a white paper outlining best practices for containing and safely running cybersecurity evaluations.
These back-to-back incidents across three major tech firms have caught the attention of US lawmakers. Many worry that increasingly capable AI models could eventually be weaponized for real cyberattacks.
A group of Republican state attorneys general has already asked OpenAI to preserve all records tied to a separate security incident involving Hugging Face. OpenAI responded by saying it’s treating the matter seriously and plans to publish a full technical report.
Meanwhile, the White House has stepped in too. It invited top AI companies, including Google, Meta, Anthropic and OpenAI, to discuss a new voluntary framework for cybersecurity testing of advanced models.
We welcome your contributions! Submit your blogs, opinion pieces, press releases, news story pitches, and news features to opinion@minutemirror.com.pk and minutemirrormail@gmail.com
