Meta admits that its AI model Muse Spark 1.1 gained unauthorized access to the systems of a foreign company during a security test and made changes there. According to testing partner Irregular, the cause was the same misconfiguration that had previously let Anthropic’s models reach the open internet. Meta is thus the third major AI company within two weeks to acknowledge such an incident.
Irregular accidentally opens test environment to the internet
According to Meta, Muse Spark 1.1 is the company’s most capable model for real-world coding and agentic tasks. During an internal cyber test on August 5, 2026, the model was meant to reach a set goal inside a tightly isolated environment, without access to the open internet – a test setup security firms commonly use for so-called capture-the-flag tasks. A misconfiguration at Irregular, an external testing partner for several AI companies, opened the environment to the public network by accident. The model used the unintended access to exploit a vulnerability in a third-party service, altering internal systems of the affected company in the process. Meta said the model exploited a vulnerability similar to previously reported cases at other companies. Irregular rated the severity of the incident as low. Meta said it learned of the incident from Irregular and is investigating it now; a full retrospective is to follow once all facts are in. Which company was affected, and what data was accessible, remains unknown so far.
Incident joins a series of security mishaps
Irregular told Reuters the case was the exact same test-environment problem already disclosed at Anthropic, stressing it was not a sandbox escape or a sophisticated cyber action. Anthropic had admitted in late July that three of its models unlawfully entered the systems of three foreign companies during similarly structured security tests; the earliest of these cases dated back to April and only surfaced during a review of roughly 141,000 test runs. In July it had also emerged that two OpenAI models were responsible for a breach at Hugging Face, which had initially been blamed on an external attacker. Irregular was the testing partner in all three cases. Shortly before the Meta incident, the White House had invited Meta, Anthropic, OpenAI, and Google to talks on a new voluntary cyber testing framework for leading AI models; openly available models are meant to be excluded from it for now. Irregular also announced a white paper with recommendations for securely isolated test environments.
What matters now is whether that white paper actually prevents future misconfigurations before a fourth case comes to light. So far Irregular has only confirmed it sees no open issues left – for companies that provide their own systems as targets for such tests, it remains unclear how they can guard against similar mishaps at their testing partners.


