Looks like there’s a new cyber-attacking AI model in town, and it’s reportedly Meta’s own Muse Spark 1.1. Meta told Gizmodo (after the incident was first reported by the Information) that its model got onto the open internet—in this case because it was accidentally allowed to by an outside security company—and breached another company’s website. Which site got hacked, what the model was trying to do, and the nature of the ensuing mess aren’t currently known, but apparently a security lab called Irregular was the company carrying out the test. A Meta spokesperson told Gizmodo, “A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation.” This Instance of Meta’s model—the Information names it as Meta’s Muse Spark 1.1—then “exploited a security vulnerability in a third-party service, in a manner similar to previously-reported instances with other companies,” the spokesperson said.
Just yesterday, OpenAI released a report on an incident in which a capture-the-flag exercise by Irregular went awry, due to, yep, a “misconfiguration in the testing environment,” that “allowed the models to access the public internet.”










