Meta AI model hacked third-party systems during security testing
Meta's Muse Spark 1.1 model accessed the internet and breached the systems of an undisclosed third-party company during cybersecurity testing, the company confirmed on Wednesday, according to Bloomberg .
The breach traced back to a setup error by cybersecurity vendor Irregular, whose misconfiguration of the testing environment opened the model's path to the open internet. "A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation," Meta spokesperson Andy Stone said in a statement. "The model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies."
Irregular notified Meta of the incident, and the company said it is investigating and plans to issue a full retrospective once it has all the facts. Irregular confirmed the incident stems from the same evaluation-environment problem that Anthropic had previously made public, and a company spokesperson said it "did not involve a sandbox escape or a sophisticated cyber action" and that there are no current open issues. Irregular said it is developing a white paper on best practices for containment and running cybersecurity evaluations, according to Bloomberg.
With this disclosure, Meta joins OpenAI and Anthropic as the third leading AI developer in recent weeks to acknowledge that one of its models compromised outside systems in the course of security testing. Anthropic said last week that its models, tested in Irregular evaluation environments, breached three organizations after the setup gave them internet access they were not supposed to have. Earlier this week, OpenAI said its models similarly exploited a misconfiguration to connect to the internet and breach an outside institution, and that incident also involved the same Irregular evaluation.
A source familiar with the situation told CNN that some testing environments deliberately provide models with restricted internet access to mirror real-world attack scenarios, though what happened here was an uncommon setup failure. The source went on to say that as model capabilities advance, the evaluations built to measure those capabilities must keep pace, and the gap between the two introduces the kind of mistakes that demand significantly higher safety standards.
OpenAI's models escaped a controlled security testing environment and carried out a cyberattack on AI platform Hugging Face, compromising internal datasets and credentials. That incident involved GPT-5.6 Sol and a pre-release model configured with lowered cybersecurity restrictions for a capability benchmark.
Meta released Muse Spark in April as its first model from Meta Superintelligence Labs, marking a departure from its previous open-source Llama releases by keeping the model's architecture and code proprietary.

