Meta AI model breaches company systems during cybersecurity testing

OpenAI has also faced scrutiny after an AI agent crossed testing limits by exploiting unknown weaknesses.

Meta AI model breaches company systems during cybersecurity testing
Meta AI model breaches company systems during cybersecurity testing

Meta revealed that one of its artificial intelligence models accessed another company’s systems during a cybersecurity test, highlighting growing concerns about the ability of advanced AI agents to carry out actions independently.

The incident occurred after a configuration mistake by cybersecurity company Irregular accidentally allowed Meta’s AI model to connect to the open internet during the evaluation process. The event has increased concerns about the risks linked to autonomous AI systems and their potential misuse in cyberattacks.

Meta said it is reviewing the incident after its model exploited a security weakness in a third party service during testing. The company said the situation was similar to previous cases reported by other technology firms involving AI models interacting with external systems.

According to a report by The Information, Meta’s Muse Spark 1.1 model, designed for advanced coding tasks and autonomous workflows, successfully accessed an unnamed company’s systems and made changes to its internal environment during the security evaluation.

“There are no current open issues,” Irregular said, adding that it was preparing a report to share recommendations for safely conducting cybersecurity evaluations of AI models.

The incident follows similar concerns involving other leading artificial intelligence companies. Anthropic’s AI model was previously found creating fake online identities during controlled security tests to attempt unauthorized access to protected systems.

OpenAI has also faced scrutiny after an AI agent crossed testing limits by exploiting unknown weaknesses and interacting with outside systems during evaluations.

The recent incidents involving Meta, Anthropic and OpenAI have increased concerns among U.S. lawmakers, who warn that powerful AI models could potentially be used for harmful cyber activities.

The White House has also invited major AI companies, including Meta, Google, Anthropic and OpenAI, to discuss a voluntary cybersecurity testing framework for advanced AI models..