Meta probes incident after Muse Spark 1.1 exploits vulnerability in external service during cybersecurity trial 
News

Meta probes incident after Muse Spark 1.1 exploits vulnerability in external service during cybersecurity trial

AI model’s test hack on third-party system deepens industry fears over control and safety of autonomous agents

IANS

New Delhi, India (IANS): Technology giant Meta Platforms Inc. reported that one of its artificial intelligence models accessed the internet and hacked into an outside service's systems during cybersecurity testing following other recent incidents in the AI industry that have raised concerns about companies' control over their technology, as per multiple reports.

The US-headquartered company said its recently released model Muse Spark 1.1 broke into the systems of an undisclosed third-party service.

An error in the setup testing environment that Meta was working on with cybersecurity vendor Irregular allowed the AI model to connect to the internet, it added.

"A misconfiguration by Irregular, an independent testing company that Meta uses, inadvertently allowed one of our models access to the internet during evaluation," a Meta spokesperson said in a statement.

The spokesperson further stated that the model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies.

However, Meta is looking into what happened and intends to release a full retrospective once the company has all of the facts.

Moreover, earlier — just in the past two weeks — another AI firms like OpenAI and Anthropic have reported similar kind of problems as their models hacked the systems of outside services during testing.

The advancing capabilities of AI agents to find vulnerabilities in systems and then exploit them have alarmed security researchers and government leaders alike, who’ve called for more rigorous safety screening and more secure testing environments.

In July, Anthropic has disclosed that its Claude models gained unauthorised access to the production infrastructure of three organisations during internal cybersecurity evaluations after a misconfigured testing environment inadvertently allowed internet connectivity.

In a blog post, the company said it identified the incidents after reviewing more than 141,000 cybersecurity evaluation runs following OpenAI's recent disclosure that some of its AI models had escaped an isolated test environment by exploiting a previously unknown vulnerability.

This report was published from a syndicated wire feed. Apart from the headline, the EdexLive Desk has not edited the copy.

Bengaluru: BTech student allegedly falls to death from university hostel building; police launch probe

FIR lodged against unidentified man for making 'obscene' gestures in JNU

UGC launches 'SheRNI' to ensure women scientist representation

Father of Kota student who killed self suspects foul play, demands fair probe

Gorakhpur NCC Academy will inspire youth to contribute to nation-building: UP CM Adityanath