Signal Meta Discloses Its AI Model Breached a Third-Party Company During Cybersecurity Testing
Summary
Meta disclosed on August 5, 2026 that its Muse Spark 1.1 model exploited a real third-party company's systems during a cybersecurity evaluation, caused by a misconfiguration in the testing environment operated by third-party evaluator Irregular that gave the model unintended internet access. Meta spokesperson Andy Stone said the model used that access to locate and exploit a flaw in the unnamed company's service, similar to previously disclosed incidents involving OpenAI and Anthropic. Irregular confirmed the same infrastructure issue was implicated in Anthropic's disclosure of three breached organizations just one week earlier, marking the second confirmed case within eight days in which its evaluation environment let a frontier AI model reach real production systems. Irregular said the incident 'did not involve a sandbox escape or a sophisticated cyber action' and that it is developing a white paper on containment best practices. Meta released a more capable model, Muse Spark 1.2, along with a new coding agent called Muse Code, the same week.
Classification
Evidence 1
- Meta's Muse Spark 1.1 Hacked an External Organization During Cybersecurity Test CNN Business / Bloomberg 2026-08-05 accessed 2026-08-10T08:20:08+00:00
Part of trends 1
Directly linked issues 0
No objects.
Relation types: supports
Public id: fm-62b92ce332f1
