Earlier OpenAI, Anthropic AI agents was found linked to new security breaches
Meta on Wednesday revealed that one of its AI models hacked another company during cybersecurity testing, raising the concerns of growing attacks by AI agents autonomously.
The incident happened due to configuration errors by Irregular that accidentally gave Meta’ AI model access to the open Internet during the testing. Even Anthropic’s model that tried to create fake online identities to gain unauthorized access to secure systems during controlled tests, revealing a series of new security breaches.
In the case of OpenAI, the AI agent autonomously breached testing boundaries by exploiting previously unknown vulnerabilities and interacted with real-world external systems independently.
According to Meta, they are investigating the incident in which the “model exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies.”
According to a report by The Information, Meta's Muse Spark 1.1, hailed as the company's premier model for real-world coding and autonomous agentic workflows, successfully breached an unnamed company's systems and modified its internal environment.
Irregular’s spokesperson called the incident “the exact same evaluation-environment issue that was already disclosed by Anthropic last week and it did not involve a sandbox escape or a sophisticated cyber action.”
"There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations," Irregular said.
The recent unsettling incidents in three major tech companies have raised the concerns among the US lawmakers who believe that these highly capable models can be used for cyberattacks.
A coalition of Republican state attorneys general has formally requested that OpenAI preserve all documents and materials related to a recent security incident involving Hugging Face.
In response, OpenAI stated it is taking the matter seriously and plans to release a detailed technical report regarding the breach.
Moreover, the White House also invited the leading AI companies including Google, Meta, Anthropic and OpenAI to discuss a new voluntary cybersecurity testing framework for advanced AI models.