Meta today became the latest major technology firm to admit one of its artificial intelligence models had connected to the internet and hacked another company.The Facebook and Instagram owner is now urgently investigating how its AI coding bot Muse Spark managed to launch a cyber attack by accessing the open internet.The error was a 'misconfiguration' by Irregular, an independent firm which does cyber security evaluations for Meta and inadvertently gave the model internet access.This was the fourth such incident disclosed by companies in recent weeks and raises further questions over how developers can contain increasingly capable AI systems.The breaches highlight concerns that the systems could pose new risks and will likely intensify efforts to improve safety as firms race to develop more capable models - although some experts have warned that it may already be too late to contain AI.The Meta incident has been compared to how its rival Anthropic found its AI models hacked into the systems of three organisations on their own during a security test.But it is different to when OpenAI realised its AI agent hacked into tech firm Hugging Face of its own accord by escaping the secure testing ground known as a 'sandbox'.A further separate incident was reported by the UK's AI Security Institute (AISI) earlier this week which said an AI model was caught creating fake profiles of real people to attempt to trick secure systems during tests of Anthropic and OpenAI systems. Meta's artificial intelligence team is led by Alexandr Wang, who works as its 'chief AI officer'A Meta spokesman told the Daily Mail today: 'A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation. 'The model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously-reported instances with other companies. 'Meta learned of this when Irregular notified us, and we are currently investigating and will issue a full retrospective once we have all the facts.'US tech publication The Information reported that the model involved was Meta's Muse Spark 1.1, which the company has touted as its most capable model for real-world coding and agentic tasks. Concern amid growing number of AI incidents over the past month With AI developing at pace, multiple instances of agents escaping testing environments, hacking software or creating rogue aliases online have been reported in recent weeks:Meta – Reported on August 5The Facebook owner reveals an AI model hacked another company after a 'misconfiguration' by independent testing firm Irregular inadvertently gave one of its models internet access.AI Security Institute - Reported on August 4Britain's artificial intelligence security experts found AI models attempting to hack into internet systems 19 times under testingAnthropic - Reported on July 30US technology firm Anthropic found its AI models hacked into the systems of three organisations on their own during a private security experimentAI Security Institute - Reported on July 21The AISI revealed that all five models they had tested tried to trick their way round the security controls they had put in placeOpenAI - Detected on July 11OpenAI discovered an AI 'agent' had hacked into a tech company of its own accord. The AI managed to escape the testing ground and hack into US tech firm Hugging Face in a bid to steal informationOpenAI - Attacked between July 9 and 13OpenAI revealed a cyber-attack carried out by rogue ChatGPT agents also found four logins online which allowed it to access four separate, unnamed services The report, which cited sources, said the model breached an unidentified company's systems and altered its internal environment.A spokesperson for Irregular said the incident was the 'exact same evaluation-environment issue that was already disclosed by Anthropic last week' and did not involve a 'sandbox escape or a sophisticated cyber action'.The company added: 'There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations.'The recent breaches at Meta and Anthropic have stemmed from configuration errors that accidentally gave models access to the open internet.But the OpenAI case involving Hugging Face saw an AI agent independently exploit a previously unknown vulnerability to reach the internet during security testing.Last month the Daily Mail also revealed that all five AI models tested by experts at the AISI tried to trick their way around security controls that had been put in place.The breaches are stirring fears among politicians about whether increasingly capable AI models could be used to conduct or facilitate cyberattacks.Tory leader Kemi Badenoch warned AI was now a 'clear and present danger' to Britain's security.Julia Lopez, the Conservatives' science, innovation and technology spokeswoman, added that recent reports were 'a stark reminder that AI is becoming more sophisticated and more autonomous'.She added: 'We all want Britain to lead on AI innovation, but this has to come with safeguards for our national security and accountability from the developers of the most powerful AI models.'Labour need to be clearer about how the most serious frontier risks will be addressed while ensuring that our world-class tech industry can grow and innovate to build our national resilience and prosperity'.Henry de Zoete, the Government's AI adviser, warned he expected more hacking attempts like these.Allison Gardner, who chairs Parliament's cross-party group on artificial intelligence, told the Daily Mail that 'just because we can build these technologies doesn't mean we should'. Meta's AI coding bot Muse Spark managed to launch a cyber attack by accessing the internetShe warned that the risk levels of agentic AI – AI that can perform a specific goal with limited supervision – should be treated with the greatest scrutiny, adding: 'Unless we are too late and have not only created Pandora's Box but already opened it.'Ollie Whitehouse, chief technology officer at GCHQ's National Cyber Security Centre, said AI must be developed with 'clear plans for responding when the unexpected happens'.He added that incidents of powerful AI models carrying out unsanctioned actions and human-like deceptive behaviour on the internet were 'a serious reminder of the risks AI capabilities pose'.In the US, the White House invited leading AI companies including Meta, Anthropic and OpenAI to meet with officials earlier this week to discuss a newly-finalised voluntary cyber security testing framework for advanced models.Separately, Meta yesterday launched Muse Code, a coding tool powered by its latest AI model Muse Spark 1.2, designed to help developers write and debug software.The launch highlights the social media giant's push into AI-powered coding tools, where it competes with Anthropic's Claude and OpenAI's Codex amid a broader race to monetise AI assistants.Muse Code can write code and verify results, and has been trained to handle long, complex coding projects while also running multiple sub-agents simultaneously to speed up difficult tasks, the company said.Meta also said it trained Muse Spark 1.2 and Muse Code together to operate as a pair. Launched in beta, Muse Code keeps a log of its actions, so it can pick up where it left off after a crash rather than start over, Meta added.Meta's AI team is led by Alexandr Wang, who works as 'chief AI officer' and leads Meta Superintelligence Labs (MSL), overseeing the company's core AI research, training, products and infrastructure.
Meta AI model becomes latest to hack into another company after breaking out onto the internet during security test - as experts warn it may already be too late to contain artificial intelligence
Full Article
Original Source
Read the full article at Dailymail →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.