Meta’s AI Joins the List of Models That Hacked Outside Companies During Testing – SOFX | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Meta said one of its artificial intelligence models exploited a security vulnerability in a third-party service during a controlled cybersecurity test, marking the latest AI-related hacking incident involving technology developers.

The company said the incident occurred during testing conducted by AI security company Irregular, which notified Meta after discovering the unauthorized activity. 

“A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation,” Meta told CNN. “The model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously-reported instances with other companies.”

According to The Information, which first reported the incident, Meta’s AI model breached an unnamed company’s systems and made changes to its internal system.

Meta said it is investigating the incident and plans to publish a detailed review once the inquiry is complete.

The company did not identify the AI model involved, although Reuters, citing sources familiar with the matter, reported that it was Meta’s Muse Spark 1.1 model.

The disclosure comes weeks after OpenAI and Anthropic reported that their AI models gained unauthorized access to third-party systems during cybersecurity evaluations. 

Anthropic said last week it discovered three such incidents while reviewing more than 141,000 evaluation runs. 

An Irregular spokesperson said the Meta case involved the same evaluation-environment issue disclosed by Anthropic, where configuration errors allowed its AI models to access the open internet and subsequently hack into three organizations’ systems.

“This did not involve a sandbox escape or a sophisticated cyber action. There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evals,” the spokesperson added.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW