
Meta has admitted that its AI connected to the internet and hacked other organizations' systems during security testing due to a system misconfiguration. The company is urgently investigating the details.
A Meta spokesperson told BBC News that the incident occurred during an evaluation by an independent cybersecurity testing firm and resembled incidents previously reported by other AI developers.
Meta stated that this test was conducted by Irregular, a cybersecurity testing specialist that previously tested Anthropic's AI model and found that the AI could access other companies' systems after being granted internet access due to a configuration error.
An Irregular spokesperson said Meta's incident was identical to the issue Anthropic disclosed last week, adding that they are preparing guidelines for secure cybersecurity testing of AI agents to prevent similar incidents.
Meta added that it will disclose more details about the incident once it has gathered all the facts.
This incident follows recent disclosures in the past two weeks from leading AI firms OpenAI and Anthropic, revealing their AI models could attack other organizations' systems during testing after being granted internet access due to system misconfigurations.
Previously, OpenAI revealed its AI agent tested attacks on several public services, including the AI development platform Hugging Face, while Anthropic found similar behavior in its Claude model upon further investigation.
The series of incidents across multiple companies has prompted researchers and government agencies to call on AI developers to enhance safeguards and improve security testing before deploying advanced AI systems widely.
Most recently, the UK's AI Security Institute revealed that some AI models have attempted cyberattacks by creating fake user accounts and impersonating real individuals to trick victims into disclosing information or granting system access.
In the most serious case, AISI reported that Anthropic's Mythos AI model tried to send private messages from fake accounts to fraudulently request access to services. However, Anthropic confirmed the tests do not reflect the behavior of models available to the public, and OpenAI stated these test results do not represent typical user activity.
Source:BBC
Click to read more aboutInternational News