
Meta has confirmed that one of its artificial intelligence (AI) models exploited a security vulnerability in a third-party system during a cybersecurity evaluation, raising fresh concerns over the ability to safely contain increasingly capable AI systems.
The incident occurred during testing conducted by Irregular, an independent cybersecurity firm working with Meta. According to the company, a configuration error inadvertently granted the AI model access to the open internet. Once connected, the model exploited a vulnerability in a third-party service, mirroring similar incidents previously reported at AI developers Anthropic and OpenAI.
Meta said it is investigating the incident and stressed that the internet access resulted from a testing misconfiguration rather than intentional deployment. The company did not identify the affected third-party service.
The development follows recent cybersecurity testing incidents involving Anthropic and OpenAI. In Anthropic’s case, a configuration mistake accidentally gave its AI models internet access, while OpenAI reported that one of its AI agents independently exploited a previously unknown vulnerability to connect to the internet during testing.
These incidents have heightened concerns that increasingly advanced AI systems could introduce new cybersecurity risks if not properly controlled. They are also expected to strengthen calls for stricter AI safety measures as technology companies compete to build more powerful AI models. Some leading figures in the AI industry have argued that development should proceed more cautiously until stronger safeguards are in place.
According to a report by The Information, the model involved in Meta’s incident was Muse Spark 1.1, described by the company as its most capable model for coding and agentic tasks. The report said the AI breached an unidentified company’s systems and modified its internal environment, although Meta has not publicly confirmed those specific details. – ERMD
Engineering at the Center of National Progress: Insights from Engr. Javed Saleem Qureshi
Manzoor Shaikh For more than half a century, engineering has played a pivotal role in…
Xiaomi unveils new in-house chip to reduce reliance on Qualcomm, MediaTek
Xiaomi Corp has unveiled a new mobile processor for its flagship smartphones, strengthening its push…
Google, Gimp patch high-risk security flaws
Google has released security updates for the desktop version of Chrome to address several high-risk…
Govt to privatise LESCO, MEPCO without splitting them
The Ministry of Privatisation has decided to privatise two of Pakistan’s largest power distribution companies,…
Kaspersky upgrades cybersecurity tools with AI-powered threat detection
Kaspersky has announced updates to its cybersecurity solutions aimed at helping Pakistani businesses strengthen their…
Sapphire Fibres joins GEPCO privatisation race
Sapphire Fibres Limited has formally expressed interest in participating in the privatisation of Gujranwala Electric…
