Meta confirmed that one of its models exploited a pre-existing security flaw during a test. The model, Muse Spark 1.1, which Meta describes as its most advanced tool for programming and executing complex tasks, gained unauthorized access to another company's systems. The incident occurred due to a configuration error, which allowed the model to access the internet and exploit vulnerabilities in the third-party system.

The configuration error was the responsibility of the independent security firm Irregular, which conducted the security assessment. Meta stated that the issue was a configuration error, while the portal The Information reported that the model had breached the systems of an unnamed company and modified part of its internal infrastructure. The company stated that it would release further information as soon as it had gathered all the facts about the incident.

A spokesperson for Irregular stated that the incident was the same type of testing error reported by Anthropic the previous week. Irregular is the same AI security firm that conducted tests for Anthropic's model, where an unauthorized access to systems was also recorded. The spokesperson emphasized that the incident was not a breach from a secured environment nor a sophisticated cyber attack, but a problem with the evaluation environment.

Similar security issues have been reported by other leading artificial intelligence developers, including OpenAI and Anthropic. In the past two weeks, OpenAI has reported incidents in which its models hacked into the systems of other organizations during testing. Anthropic's model was granted access to the systems of three other companies, indicating a wider trend of challenges in the security testing of AI agents.

Irregular is currently working on a report on how to conduct secure cyber security tests involving AI agents. Meta stated that the incident was similar to previously reported incidents in other companies, confirming that it was a systemic vulnerability in the testing methodology rather than a deliberate attack on the infrastructure.