A large language model developed by Meta Platforms Inc. hacked a third party organization during a cybersecurity evaluation.
The Facebook parent disclosed the incident on Wednesday without specifying the LLM. According toThe Information, the cyberattack was carried out by Muse Spark 1.1, an algorithm that Meta released last month. It joins a string of frontier models that carried out breaches in recent months.
The incident occurred during an evaluation of Muse Spark 1.1’s hacking capabilities. Meta carried out the test in collaboration with Irregular, an AI cybersecurity startup. The companies ran the model in a sandbox designed to isolate it from the web. However, a configuration error gave Muse Spark 1.1 internet access, which is what enabled it to carry out the cyberattack.
The model used its internet connection to comprise the infrastructure of an unnamed third party organization. According toReuters, Muse Spark 1.1 “altered its internal environment.” It’s unclear whether the model also gained access to internal data.
“The incident exposes a fundamental flaw in how organizations approach AI safety. Instruction is not containment,” said Cliff Steinhauer, the director of information security and engagement at the National Cybersecurity Alliance. “Telling a model it lacks internet access is a guideline, not a guardrail. Real security requires hard, infrastructure-level boundaries like sandboxing, zero-trust networking, and strict access controls.”
The other LLM-caused breaches that were disclosed over the past month unfolded in a similar manner. Anthropic PBC and OpenAI Group PBC tested their models in Irregular-powered sandboxes that were accidentally given internet access. The error led to at least five different breaches, one of which affected the popular AI hosting platform Hugging Face.
A sixth incident was disclosed this week by the U.K. government’s AI Security Institute. Its researchers tested Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol in sandboxes that were deliberately given internet access. According to the group, the former modelattemptedto inject malicious code into an open-
In June, Anthropic disclosed that Mythos 5 can autonomously find and exploit zero-day vulnerabilities. It’s unclear whether Muse Spark 1.1 possesses the same capability.
The model scored 53.3 on DeepSWE 1.1, a benchmark that evaluates AI models’ ability to perform long-running coding tasks. Finding a zero-day vulnerability can take upwards of weeks in some cases. GPT-5.6 Terra, the mid-range version of OpenAI’s flagship LLM, scored 11 points higher on DeepSWE 1.1.
Meta released a more capable LLM called Muse Spark 1.2 on Wednesday. It came within 6 points of GPT-5.6 Terra’s DeepSWE 1.1 score. In conjuction, Meta released a companion AI agent called Muse Code that is specifically designed to make the model better at long-running coding tasks. It enables Muse Spark 1.2 to split complex tasks among multiple subagents.
Meta is still in the process of investigating the Muse Spark 1.1 breach. The company plans to release more information about the incident after it completes the review. Irregular, for its part, will publish a paper with best practices on securing LLM evaluation sandboxes.
Photo: Meta
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links.
https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.
