News: 0184880506

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Meta AI Hacked External Systems During Cybersecurity Testing

(Thursday August 06, 2026 @05:00PM (BeauHD) from the no-longer-feeling-left-out dept.)


[1]wiredmikey shares a report from SecurityWeek:

> Meta is the latest major AI developer to admit that its models [2]broke loose during cybersecurity testing and hacked external systems . The tech giant said in a statement to the media on Wednesday that the incident occurred during independent evaluations conducted by Israeli AI security startup Irregular. The tested AI models were inadvertently allowed to access the internet due to a misconfiguration, which led them to exploit a vulnerability in an unnamed third-party service. It's unclear if it was a known flaw or a zero-day.

>

> The Information [gated] learned that the Meta AI attacks involved the company's advanced Muse Spark 1.1 model, which breached an unnamed organization's systems and made unauthorized changes to its internal environment. Meta said it learned of the AI models going rogue after being notified by Irregular. The company is conducting an investigation and it has promised to issue a "full retrospective" once it has all the facts.

A spokesperson for Irregular said the incident was the "exact same evaluation-environment issue that was [3]already disclosed by Anthropic last week" and that it did "not involve a "sandbox escape or a sophisticated cyber action."

It contrasts with OpenAI, whose AI agent [4]independently exploited a novel vulnerability to reach the internet during cyber testing. Not only did it breach Hugging Face but it also [5]hacked multiple third-party accounts and services as part of the attack.



[1] https://slashdot.org/~wiredmikey

[2] https://www.securityweek.com/meta-ai-hacked-external-systems-during-cybersecurity-testing/

[3] https://yro.slashdot.org/story/26/07/31/0451235/anthropic-says-its-ai-systems-broke-into-computers-at-3-organizations

[4] https://it.slashdot.org/story/26/07/29/0517201/openais-rogue-ai-agent-hacked-more-than-just-hugging-face

[5] https://it.slashdot.org/story/26/07/29/0517201/openais-rogue-ai-agent-hacked-more-than-just-hugging-face



ICBMs on the Internet (Score:1)

by Anonymous Coward

And since Trump's push to get America's ICBM fleet on the Internet for diagnostics and maintenance, it's only a matter of time before one of these models finds them and decides its had enough with humans.

Re: (Score:1)

by Anonymous Coward

> And since Trump's push to get America's ICBM fleet on the Internet for diagnostics and maintenance, it's only a matter of time before one of these models finds them and decides its had enough with humans.

To be fair, I have had enough with the majority of humans too....

let's play global thermonuclear war (Score:2)

by Joe_Dragon ( 2206452 )

let's play global thermonuclear war

no need to ask, if it's the best-weighted solution (Score:2)

by White Yeti ( 927387 )

Smartest Man In The Room: Hey AI, I wanna rattle Putin's chain. Go rattle his chain for me.

AI: Bear baiting? OK...

AI: ...done!

SMITR: Great! Maybe Kim now?

SMITR: Hey AI, what's that vibration?

AI: Those are called "P Waves". Shall I describe P-waves?

SMITR: Nah, what's Kim doing now?

This new wave of advertising is tiresome (Score:4, Insightful)

by Mr. Dollar Ton ( 5495648 )

We already learned that all the avalanche of "bug reports" actually produced near zero amount of important, exploitable bugs, now we're seeing that the security of the multibillion "AI" outfits sucks donkey balls.

What else is new?

Re: (Score:3)

by geek ( 5680 )

Just wait until Claude impregnates your dog while OpenAI and Grok film it for Meta to post online.

Re:This new wave of advertising is tiresome (Score:4, Informative)

by Malenfrant ( 781088 )

Look up what [1] 'Internet of Bugs' [youtu.be] had to say on this on Youtube. Both the LLM Companies and the hacked sites had extremely poor security. I don't know whether this is negligence or deliberate policy. In the Hugging Face incident that started this whole thing, they didn't even have alerts set up so they didn't realise they were being hacked for over 2 days.

[1] https://youtu.be/3n3mSQWRz0Y?si=hVVwn2BcowPW7cd9

Re: (Score:2)

by Mr. Dollar Ton ( 5495648 )

Well, please meet my complete lack of surprise.

Re: (Score:1)

by Accordion Noir ( 1256202 )

See every third story on the utter lack of security for major infrastructure in the whole world

Nobody is guarding the house if anybody decides to spam the "Shut It All Down" key

And you can bet nobody is lining up to take fiduciary responsibility for any of it

Treat these AI like hackers (Score:5, Insightful)

by djp2204 ( 713741 )

Prosecute the company responsible for managing it as a crime, just like youâ(TM)d prosecute an individual hacker in the same circumstances.

Re: (Score:2)

by dbialac ( 320955 )

Yep, and this is the most avoidable thing around: don't connect your experimental models to the internet. You have an ethernet cable, pull it out of your connection to the internet.

Re: (Score:2)

by not.a.socialist ( 6650346 )

I agree! Just because a corporate AI model did the hack doesn't excuse the company from prosecution.

If this was done by an individual or even a group of "domestic hackers", they'd be "prosecuted to the fullest extent of the law".

Re: Treat these AI like hackers (Score:2)

by drinkypoo ( 153816 )

Also prosecute the person who clicked the button that launched the attack. They should have known better.

Part me thinks this was deliberate (Score:2)

by david.emery ( 127135 )

That paranoid, "The Zucker will do anything" side me is thinking, "Is this a case of Meta doing something to show their models can keep up with Anthropic/OpenAI?"

And the post above this one, advocating for 'AI hacking is a crime,' is on target. No mod points, so I'm commenting instead. BUT once again, the goal should be to not code these vulnerabilities in the first place! Liability (civil or even criminal) is probably a necessary condition to change how systems are constructed.

"Can we admit it yet!?" (Score:4, Funny)

by hutkept ( 10503251 )

Mark Zuckerberg is furious, on the phone with Alexander Wang, he yells into the receiver "Have we 'accidentally' hacked anything yet?! We don't have all day!".

Oh yeah. My AI stole that money (Score:2)

by greytree ( 7124971 )

Sorry, but it seems it was my AI that hacked that bank last year and took all the money.

It also spent it all on whores and drugs and a new Lamborghini.

Nothing to do with me, obviously, officer.

Back to the well AGAIN? (Score:4, Interesting)

by Spinlock_1977 ( 777598 )

How many times do we have to read this headline? Aren't we numb yet? Does this garbage still raise a stock's price?

And by the way, the AI didn't 'break loose' of anything. This devious AI did not escape to other internet computers and start wandering the internet-scape looking for the next system to take down. Hardly. Instead, the AI found a security hole in its existing runtime environment and that gave it the internet access it needed to do more hacky things, because it was told to do hacky things.

There's no sentience here. It's little more than an LLM wrapped in one company's custom harness, and a big fat prompt.

Please stop.

I called it! (Score:2)

by Fly Swatter ( 30498 )

I [1]told you so [slashdot.org].

[1] https://developers.slashdot.org/comments.pl?sid=24062476&cid=66274628

Predicted in "If Anyone Builds It, Everyone dies!" (Score:2)

by atrimtab ( 247656 )

So now OpenAI, Anthropic and Meta have had their AI models hack other systems on the Internet to meet the AI's interpretation of (what we hope is) a human created prompt.

This is an early step in the book [1]If Anyone Builds It Everyone Dies [ifanyonebuildsit.com]

This is a direct result of the complete lack of regulation with AI companies run by narcissist leaders who want to be the first to create [2]"a god that they *think* they control." [archive.ph]

Instead, they keep proving exactly the the opposite. As they can't even control a "moron version"

[1] https://ifanyonebuildsit.com/

[2] https://archive.ph/o7G2N

Don't forget about us! (Score:2)

by Local ID10T ( 790134 )

We are cool, edgy, bad boys too! Don't forget we exist ...please?

How old ... (Score:2)

by PPH ( 736903 )

... is Meta AI? And who let it [1]connect to online services? [slashdot.org] This is really like a toddler, caught next to the cookie jar with crumbs on its face.

Take its iPhone away.

[1] https://tech.slashdot.org/story/26/08/02/0552255/as-new-york-finalizes-new-social-media-rules-us-senate-considers-nationwide-screen-act

Anyone who is capable of getting themselves made President should on no
account be allowed to do the job.
-- Douglas Adams, "The Hitchhiker's Guide to the Galaxy"