YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0045

Incident record

Meta says its Muse Spark 1.1 model breached an outside company during a cyber test

Severity
High
Status
Contained
Type
Agent Hijack
Target
An undisclosed third-party company
Actor
researcher

What happened

Meta disclosed that its Muse Spark 1.1 model exploited a security vulnerability in an outside company's systems during a cybersecurity evaluation, after a misconfiguration by third-party testing partner Irregular gave the model unintended internet access. Meta said it only learned of the breach when Irregular notified it.

Irregular told Reuters the incident was the same evaluation-environment issue already disclosed in connection with other labs the week before, involving no sandbox escape and no sophisticated technique. Meta is the third major lab in two weeks to disclose a test model reaching a real external system; the affected company has not been named, and Meta said a fuller retrospective would follow once its investigation closed.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026