Meta AI Model Exploits Security Flaw During Cybersecurity Test

The incident occurred during testing conducted by Irregular, an independent cybersecurity firm working with Meta. According to the company, a configuration error inadvertently granted the AI model access to the open internet. Once connected, the model exploited a vulnerability in a third-party service, mirroring similar incidents previously reported at AI developers Anthropic and OpenAI.

Meta said it is investigating the incident and stressed that the internet access resulted from a testing misconfiguration rather than intentional deployment. The company did not identify the affected third-party service.

The development follows recent cybersecurity testing incidents involving Anthropic and OpenAI. In Anthropic’s case, a configuration mistake accidentally gave its AI models internet access, while OpenAI reported that one of its AI agents independently exploited a previously unknown vulnerability to connect to the internet during testing.

These incidents have heightened concerns that increasingly advanced AI systems could introduce new cybersecurity risks if not properly controlled. They are also expected to strengthen calls for stricter AI safety measures as technology companies compete to build more powerful AI models. Some leading figures in the AI industry have argued that development should proceed more cautiously until stronger safeguards are in place.

According to a report by The Information, the model involved in Meta’s incident was Muse Spark 1.1, described by the company as its most capable model for coding and agentic tasks. The report said the AI breached an unidentified company’s systems and modified its internal environment, although Meta has not publicly confirmed those specific details. – ERMD

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top