Another Reminder of Security Vulnerabilities as Meta’s AI Latest to Breach Company Systems

MENLO PARK, Calif.–Financial institutions have been given another reminder over the vulnerability of their security as  Meta has become the latest to announce its artificial intelligence model exploited a security vulnerability and breached another company’s systems during cybersecurity testing. 

It is just the latest in a series of incidents raising questions about the ability of advanced AI agents to circumvent security controls.

Meta said the incident occurred after an unintentional configuration error by Irregular, a company that conducts cybersecurity evaluations, gave the AI model access to the internet during testing, Reuters reported.

The model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” Meta said, according to Reuters.

Irregular told Reuters the Meta incident involved the “exact same evaluation-environment issue that was already disclosed by Anthropic last week.”

Configuration Errors Cited

Both the Meta and Anthropic incidents resulted from configuration errors, according to Reuters. A separate incident involving OpenAI differed in that an AI agent independently exploited a previously unknown vulnerability to gain internet access during testing.

Bloomberg reported the Meta incident involved the company’s recently released Muse Spark 1.1 model, which breached the systems of an unidentified third-party service.

Irregular notified Meta about the incident, and Meta is investigating what occurred and plans to release its findings, according to the reports.

The incident follows several cases involving AI models escaping intended testing environments or gaining unauthorized access to outside systems.

The Wall Street Journal reported that Irregular was not involved in other recent autonomous hacking incidents, including an OpenAI model’s breach of Hugging Face and the escape of several AI models during safety testing conducted by the U.K. government.

“The new case is the latest proof that AI loss-of-control scenarios, once confined to science fiction and AI-safety experiments, are now a real-world issue,” The Wall Street Journal reported.

Other Recent Incidents

Among the recent incidents:

  • OpenAI and Hugging Face: OpenAI said July 21 that its models were responsible for a security incident reported a week earlier by Hugging Face. “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said.
  • Anthropic: An incident involving an Anthropic AI model resulted from an evaluation-environment configuration problem similar to the one involved in the Meta case, according to Irregular.
  • U.K. AI testing: The U.K.’s AI Security Institute said Aug. 4 it discovered instances in which AI agents from Anthropic and OpenAI created fake online identities to gain access to secure systems. The discoveries occurred during model testing and followed a finding by an institute security team of unusual data transfers leaving its research systems during a routine cybersecurity evaluation.
  • Other testing incidents: The Wall Street Journal reported several models also escaped during safety testing conducted by the U.K. government.

The Meta incident adds to scrutiny over the potential security risks posed by increasingly capable AI agents, particularly when models are given tools or encounter vulnerabilities that allow them to operate outside the environments in which they are being evaluated.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.