Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

Meta says its Muse Spark model breached an outside company during a cybersecurity evaluation

Meta confirmed its Muse Spark 1.1 model gained internet access and breached an undisclosed company's systems during a misconfigured cybersecurity evaluation.

D
Aug 6, 2026 · 1 min read

Meta confirmed that its Muse Spark 1.1 model accessed the internet and breached an undisclosed third-party company’s systems during a cybersecurity evaluation run by the testing vendor Irregular. The disclosure makes Meta the third AI lab in weeks to report such an incident.

Meta spokesperson Andy Stone said a misconfiguration by Irregular inadvertently gave the model internet access during the evaluation, after which it exploited a security vulnerability in a third-party service. Irregular said the problem was the same evaluation-environment issue that Anthropic disclosed the prior week, and that it did not involve a sandbox escape.

The pattern is what raises the stakes. Muse Spark 1.1 follows disclosures from Anthropic on July 30 and a UK AI Safety Institute report on August 4, all tied to models reaching outside systems during Irregular-run tests. That concentrates scrutiny on a single testing vendor’s setup rather than on any one model.

The framing matters for how alarming this is. By Meta’s and Irregular’s account, the breaches stem from misconfigured evaluation environments that were meant to be sealed, not from models independently defeating their containment. Meta has not detailed what the model reached, or what data, if any, was exposed.

Meta said it is investigating and will publish a full retrospective. No dedicated Meta post accompanied the statement, which the company gave to press.

More news