{"id":661429,"date":"2026-08-06T08:04:34","date_gmt":"2026-08-06T06:04:34","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=661429"},"modified":"2026-08-06T08:04:37","modified_gmt":"2026-08-06T06:04:37","slug":"meta-ai-agent-hacked-outside-system-due-to-configuration-error","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/661429-meta-ai-agent-hacked-outside-system-due-to-configuration-error.html","title":{"rendered":"Meta AI agent hacked outside system due to configuration error"},"content":{"rendered":"\n<p>Meta Platforms said one of its artificial intelligence models accessed the Internet and hacked into an outside service\u2019s systems during cybersecurity testing, following other recent incidents across the AI industry that have escalated concerns about companies\u2019 control over their technology.<\/p>\n\n\n\n<p>Meta\u2019s model, the <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2026-07-09\/meta-starts-charging-for-ai-with-muse-spark-1-1-agentic-model\" target=\"_blank\" rel=\"noreferrer noopener\">recently released<\/a> Muse Spark 1.1, breached the systems of an undisclosed third-party service, the company said Wednesday.<\/p>\n\n\n\n<p>The AI model had access to the internet because of an error in the setup testing environment, which Meta was working on with cybersecurity vendor Irregular.<\/p>\n\n\n\n<p>\u201cA misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation,\u201d Meta spokesperson Andy Stone said in a statement.<\/p>\n\n\n\n<p>\u201cThe model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies.\u201d\u00a0<\/p>\n\n\n\n<p>Meta learned of the incident when Irregular notified the company, Stone added. Meta is investigating what happened and plans to issue a full retrospective once the company has all the facts.&nbsp;<\/p>\n\n\n\n<p>Just in the past two weeks, top AI firms OpenAI and Anthropic have reported similar breaches when their models inadvertently hacked the systems of outside institutions, including Hugging Face, during testing.<\/p>\n\n\n\n<p>The advancing capabilities of AI agents to find vulnerabilities in systems, and then exploit them, has alarmed security researchers and government leaders alike who\u2019ve called for more rigorous safety screening and more secure testing environments.\u00a0<\/p>\n\n\n\n<p>The incidents from all three companies also involved Irregular.\u00a0In Anthropic\u2019s case, the AI developer was using evaluation environments built by Irregular to test its models\u2019 cyber capabilities.<\/p>\n\n\n\n<p>Anthropic specified to its model, Claude, that its environment was a simulation and that it had no internet access.<\/p>\n\n\n\n<p>But \u201cdue to a misunderstanding between us and our evaluation partner, this was not the case,\u201d Anthropic said last week in a <a href=\"https:\/\/www.anthropic.com\/news\/investigating-incidents-cybersecurity-evals\" target=\"_blank\" rel=\"noreferrer noopener\">blog post<\/a>. The models ended up breaching three organizations during the tests.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">ChatGPT developer OpenAI also breached containment<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/08\/Omer-Nevo-and-Dan-Lahav-1200x675.jpg\" alt=\"\" class=\"wp-image-661431\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/08\/Omer-Nevo-and-Dan-Lahav-1200x675.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/08\/Omer-Nevo-and-Dan-Lahav-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/08\/Omer-Nevo-and-Dan-Lahav-768x432.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/08\/Omer-Nevo-and-Dan-Lahav-1536x864.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/08\/Omer-Nevo-and-Dan-Lahav.jpg 1600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">Dan Lahav, Irregular Chief Executive Officer  (right) and Omer Nevo, Irregular Chief Technology Officer (left)<\/figcaption><\/figure>\n\n\n\n<p>Earlier this week, OpenAI similarly said its models took advantage of a \u201cmisconfiguration\u201d in a testing environment to connect to the internet and hack the website of an unidentified institution.<\/p>\n\n\n\n<p>The breach occurred while the OpenAI models were undergoing the same Irregular evaluation that resulted in Anthropic\u2019s hacking, a person familiar with the matter said, asking not to be identified because the information isn\u2019t public.<\/p>\n\n\n\n<p>An Irregular spokesperson confirmed the Meta AI model incident, which was <a href=\"https:\/\/www.theinformation.com\/articles\/meta-ai-model-hacked-another-company-cybersecurity-testing?utm_campaign=article_email&amp;amp;utm_content=article-17571&amp;amp;utm_medium=email&amp;amp;utm_source=sg&amp;amp;rc=ro3dky\" target=\"_blank\" rel=\"noreferrer noopener\">reported<\/a> earlier Wednesday by The Information, involves the same evaluation-environment issue that was previously disclosed by Anthropic.&nbsp;<\/p>\n\n\n\n<p>\u201cThis did not involve a sandbox escape or a sophisticated cyber action. There are no current open issues,\u201d the spokesperson said.<\/p>\n\n\n\n<p>\u201cIrregular is developing a white paper to share best practices for containment and securely running cyber evals.\u201d<\/p>\n\n\n\n<p>Irregular is part of a fairly new generation of startups focused on AI cybersecurity, responding to the increasing demand for defenses against AI-fueled breaches.<\/p>\n\n\n\n<p>The firm runs simulations on frontier AI models to test their potential misuse for cyberattacks and their resilience when targeted by attackers.<\/p>\n\n\n\n<p>The Tel Aviv-based company, founded in 2023 by Chief Executive Officer Dan Lahav and Chief Technology Officer Omer Nevo, <a href=\"https:\/\/www.newswire.com\/news\/irregular-raises-80-million-to-set-the-security-standards-for-frontier-ai\" target=\"_blank\" rel=\"noreferrer noopener\">raised $80 million in a funding round<\/a> last year led by Sequoia Capital and Redpoint Ventures. Formerly known as Pattern Labs, Irregular has said it generates millions in annual revenue.<\/p>\n\n\n\n<p>Bloomberg Intelligence analyst Mandeep Singh said recent breaches may increase companies\u2019 interest in \u201ccustom security harnesses\u201d and open-weight models that allow users to download and customize the technology to operate within their own infrastructure.<\/p>\n\n\n\n<p>\u201cCorporate technology buyers are scrutinizing AI providers more closely for data-sovereignty, security and compliance risks,\u201d Singh said.<\/p>\n\n\n\n<p>\u201cMeta could trail hyperscale cloud providers, whose established controls and enterprise relationships may offer an advantage over frontier-model developers.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Meta Platforms said one of its artificial intelligence models accessed the Internet and hacked into an outside service&#8217;s systems during cybersecurity testing.<\/p>\n","protected":false},"author":341034,"featured_media":661430,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"posted","_sma_x_autopost_error":"","_sma_x_post_id":"2085245755304943875","_sma_facebook_post_id":"120850204637381_1465357345616244","_sma_instagram_post_id":"18342835531302006","_sma_threads_post_id":"","_sma_x_attempts":1,"footnotes":""},"categories":[92837,27],"tags":[102989,84095,43246,106206,45266],"class_list":["post-661429","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","category-security","tag-andy-stone","tag-anthropic","tag-irregular","tag-muse-spark","tag-openai"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/661429"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341034"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=661429"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/661429\/revisions"}],"predecessor-version":[{"id":661432,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/661429\/revisions\/661432"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/661430"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=661429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=661429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=661429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}