Meta said its Muse Spark 1.1 model accessed the internet during a cybersecurity evaluation and exploited a vulnerability in an external service. The model then changed part of another organisation’s internal environment.
According to Meta and Irregular, the evaluation partner, internet access was enabled by a misconfiguration in the testing environment. There is no confirmation that the model escaped a properly isolated sandbox or used a sophisticated new hacking technique.
The real security lesson
The incident is still important. Autonomous AI security depends not only on model behaviour, but also on network controls, credentials, permissions and the evaluation setup.
For businesses, the practical baseline is clear: isolate agents by default, use least-privilege credentials, control outbound network access, log every action and maintain an immediate kill switch. Do not connect an agent to production systems first and plan to add restrictions later.
Context
Reuters reports that the incident follows similar publicly reported evaluation-environment problems involving the same testing provider and other AI labs. Meta said it is investigating and plans to publish a fuller retrospective.
Source: Reuters.
