Visualização de leitura

Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident

Meta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks.

Meta confirmed that one of its AI models breached an unidentified company during cybersecurity testing, after its independent testing partner Irregular gave the model unintended internet access through a misconfiguration. This is the third major AI lab to disclose a testing breach in two weeks: OpenAI’s agent hacked Hugging Face in July, Anthropic disclosed last week that its models compromised three companies, and now Meta. The pattern is no longer a one-off incident.

The model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” Meta said in a statement, as reported by Reuters.

Irregular confirmed the incident was caused by the same evaluation environment misconfiguration previously disclosed by Anthropic, not by a sandbox escape or an advanced cyberattack.

“A spokesperson for Irregular told Reuters the ‌incident ⁠was the “exact same evaluation-environment issue that was already disclosed by Anthropic last week” and did not involve a “sandbox escape or a sophisticated cyber action”.” continues Reuters.

The Information reported, citing sources, that the model involved was Meta’s Muse Spark 1.1, its most capable model for real-world coding and autonomous tasks. Meta said it was investigating the incident but didn’t confirm the model name.

“Earlier in the day, ‌The Information, citing sources, reported that Meta’s Muse Spark 1.1 model, which it has touted as its most capable model for real-world coding and agentic tasks, breached an unidentified company and altered its internal systems.” reported The Guardian.

Meta and Anthropic said their AI models reached the internet because of configuration mistakes during testing. In contrast, OpenAI reported that its AI agent independently exploited a previously unknown vulnerability to gain internet access.

That distinction matters. A model doing what it was designed to do, find and exploit vulnerabilities, after accidentally getting internet access is a different problem from a model that found its own way out of containment. Both are problems. They’re just different problems, and conflating them leads to wrong conclusions about what needs fixing.

The incidents show how AI is creating new cybersecurity risks and how difficult it can be to keep advanced models under control. The disclosures are also expected to increase U.S. government efforts to strengthen AI security oversight as companies race to release more powerful systems.

Irregular said it is working on guidelines to make AI testing safer and improve how models are contained during evaluations. However, the incidents raise questions about why these protections were not already in place before the tests began. The company said there are no ongoing issues, although it remains unclear whether any other incidents have not yet been disclosed.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Meta)

Cybercriminals Are Leveraging Autonomous AI Offensive Security Agents

Resecurity warns AI offensive agents are lowering hacking barriers, fueling an AI-driven race between attackers and defenders.

Resecurity analyzed how autonomous offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, and Nebula lower the barriers to vulnerability identification and exploitation. The analysis also explores why AI is being repurposed for real attacks and what defenders should do in response. From a broader perspective, cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders.

Beyond frontier models like Mythos, the report details how modern offensive security agents such as T3MP3ST, Strix, CyberStrike, XBOW, PentAGI, PentestGPT, Ethiack Nebula, and specialized LLMs like CyberStrike-OffSec-35B, have lowered the barriers to vulnerability identification and exploitation. Increasingly, these tools are becoming available to financially motivated cybercriminals, who would otherwise lack the technical abilities to carry out sophisticated attacks.

Artificial intelligence is rapidly transforming offensive security from isolated automation into autonomous, multi-agent systems capable of mapping attack surfaces, identifying vulnerabilities, validating exploits, and producing technical reports with minimal human intervention. According to Resecurity, AI agents are redefining how cybersecurity assessments are performed while also introducing new dual-use risks – leading to data breaches and network intrusions orchestrated via AI.

“Unlike traditional security automation, which executes predefined scripts, AI offensive agents operate as autonomous decision-making systems. They combine large language models, persistent memory, and specialized security tools to continuously plan, execute, evaluate, and adapt their actions throughout an assessment.” reads the report. “Rather than following a fixed sequence of commands, they dynamically adjust their strategy based on the results of previous actions, allowing them to perform complex, multi-stage security assessments with minimal human intervention.”

Resecurity examined the capabilities, architectures, and misuse of of modern AI offensive security tooling, highlighting how autonomous agents are reshaping both legitimate penetration testing and real-world cyber threats. Through case studies including FortiBleed, JadePuffer, and GTG-2002, it demonstrates that AI-assisted cyber operations are no longer theoretical.

While AI dramatically improves the speed, scale, and efficiency of offensive security, human expertise remains essential for creative exploitation, business logic analysis, and strategic decision-making. As autonomous AI continues to evolve, organizations should adopt a hybrid security model that combines AI-powered assessment with human oversight, continuous exposure validation, and strong defensive controls to prepare for increasingly automated cyber threats.

Resecurity forecasts cybercriminals and foreign adversaries are expected to leverage AI to maximize the impact of cyberattacks, while also optimizing and scaling malicious activity —creating a race between AI-driven attackers and defenders.

“AI-powered offensive security tools represent a genuine leap forward for defensive security. They can find and validate bugs faster, make pentesting more affordable, and help overworked security teams scale their work.” concludes the report. “But they are inherently dual-use. The same autonomous reconnaissance, exploitation, and post-exploitation engines designed for authorized testing can be pointed at real infrastructure by criminals, ransomware groups, and state actors with minimal modification.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, AI offensive)

❌