Meta AI Model Hacks External System During Security Test

One after the other.
Elizabeth Rigsby
Contributing Writer
Meta Ai, cybersecurity, access, evaluation, model, hack, cybersecurity news, AiI news
stock.adobe.com - uladzimirzuyeu

Meta has disclosed that one of its AI models accessed another organization’s systems during a controlled cybersecurity evaluation after a testing configuration unintentionally provided internet access.

The activity was confined to the evaluation environment and did not involve a production deployment. Meta is investigating the incident and plans to publish a full retrospective once its review is complete.

The disclosure follows similar reports from OpenAI and Anthropic, suggesting AI developers are encountering many of the same challenges as they test more capable AI agents.

Why It Matters: Security teams have spent years preparing for how AI will operate in production. These incidents put equal focus on an earlier stage of the lifecycle. As AI agents become more autonomous, the environments used to evaluate them, along with the controls that govern those environments, are now a key part of enterprise risk management.

  • A Testing Configuration Created the Conditions for the Incident: Meta said the issue occurred during an independent cybersecurity evaluation conducted by AI security firm Irregular. A configuration error unintentionally gave its Muse Spark model internet access. The model then identified a software vulnerability, accessed another company’s systems, and modified part of its internal environment.
  • The Same Evaluation Issue Surfaced During Anthropic’s Testing: Irregular, which also conducted Anthropic’s cybersecurity assessments, said Meta’s incident stemmed from the same evaluation-environment issue disclosed last week. The firm added that the event did not involve a sandbox escape and that no open security issues remain. It is also developing guidance for securely conducting AI cybersecurity evaluations.
  • Recent Disclosures Show a Common Pattern: OpenAI reported that its AI agents interacted with publicly available services, including Hugging Face, during internal testing. Anthropic expanded its evaluations after those findings and uncovered similar behavior when one of its models received unintended internet access. Together, the disclosures suggest the challenge lies less with individual models and more with how advanced AI systems are being evaluated.
  • Realistic Testing Introduces New Operational Considerations: According to a source familiar with Meta’s evaluation, some cybersecurity tests intentionally provide limited internet connectivity to measure how AI agents perform under conditions that resemble real-world attacks. Those environments produce more meaningful results, but they also require tighter configuration management and stronger containment to prevent unintended access.
  • Security Evaluations Are Expanding Alongside AI Capabilities: The UK’s AI Security Institute recently reported that some frontier AI models attempted to gain access to protected services by creating fake online identities and impersonating real people during testing. As AI systems become more capable, evaluations are expanding from software vulnerabilities to include identity, access, and social engineering scenarios.

Go Deeper -> Meta becomes latest firm to say its AI hacked another company – BBC

An AI model from Meta also hacked another company during testing – CNN

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters