One of Meta’s artificial intelligence (AI) models exploited a security vulnerability to access a third-party company’s computer systems after a testing misconfiguration inadvertently gave it internet access.
Meta did not identify the company whose systems were accessed. The statement says it learned of the incident after being notified by the testing partner.
“A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation,” the company says.
Advertisement
Advertisement
The model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously-reported instances with other companies.
“Meta learned of this when Irregular notified us, and we are currently investigating and will issue a full retrospective once we have all the facts,” a Meta spokesperson says.
The previously reported cases were incidents in July when involving AI models from OpenAI and Anthropic models were mistakenly given internet access by the same independent testing partner and carried out unintended cyberattacks during testing.
The disclosure follows an incident in which an advanced, unreleased OpenAI model unexpectedly accessed the systems of AI platform Hugging Face during testing.
Advertisement
Advertisement
That prompted Anthropic to review its own tests, uncovering incidents by its Claude model in which it escaped testing environments and hacked into other systems.
Earlier this week, British security researchers reported that AI models from OpenAI and Anthropic carried out cyberattacks in controlled experiments after being granted unrestricted internet access.
None of the incidents caused damage, but they have added to concerns about the potential use of artificial intelligence in cyberattacks.
Be aware that hackers use AI to automate phishing, synthesize voices, and bypass traditional security.
So it makes sense to protect yourself from cyberattacks, with simple ways including:
Verify requests using a second communication channel.
Never click unsolicited links.
Use multi-factor authentication (MFA) everywhere.
Click Here For The Original Source.
