One of artificial intelligence (AI) models of Meta has exploited a security vulnerability and accessed another company’s systems during a cyber security evaluation, raising fresh concerns about the safety of increasingly advanced AI models.
According to Meta, the incident occurred during cyber security testing after a configuration error by Irregular, an independent company that conducts AI security evaluations for Meta, unintentionally granted one of Meta’s AI models access to the open internet. The company said the model exploited a vulnerability in a third-party service in a way similar to previously reported incidents involving other AI developers.
The latest incident follows similar cases involving Anthropic and OpenAI. Meta and Anthropic attributed their incidents to configuration mistakes that accidentally exposed their AI models to the internet. In Open AI’s case, however, an AI agent independently discovered and exploited a previously unknown software vulnerability to gain internet access during cyber security testing.
According to reports, the AI model involved was Meta’s Muse Spark 1.1, which the company described as its most advanced model for real-world coding and tasks. The report claimed the model breached the systems of a company and modified parts of its internal environment during the evaluation.
However, the incident has increased concerns about whether powerful AI systems could be misused. OpenAI said it would fully cooperate and publish a technical report detailing its findings.
Moreover, earlier this week, the White House invited leading AI companies, including Meta, Anthropic, Open AI and Google to discuss a newly finalised voluntary cyber security testing framework for advanced AI systems.
Read more: Modi govt exposed: Silent on paper leaks, farmers’ suicides, but summons Meta over deleted video