Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

August 6, 2026

Toolkit Hidden Inside Oracle Database Evades Endpoint Tools

August 6, 2026

Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident

August 6, 2026
Facebook X (Twitter) Instagram
Thursday, August 6
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
News

Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident

Team-CWDBy Team-CWDAugust 6, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Meta has confirmed that one of its AI models exploited a vulnerability in a third-party service during testing, joining OpenAI and Anthropic in reporting similar incidents.

Meta said the incident occurred during testing by independent firm Irregular.

A misconfiguration by Irregular allowed one of Meta’s models to access the internet during evaluation. The AI then went on to exploit a security vulnerability in a third-party service.

The tech giant said the exploit occurred in a manner similar to previously-reported instances with other companies.

“Meta learned of this when Irregular notified us, and we are currently investigating and will issue a full retrospective once we have all the facts,” said a statement by a Meta spokesperson sent to Infosecurity.

Separately, on August 4, Open AI published an update describing how two external testing partners identified incidents in which testing configurations and controls allowed model activity to extend beyond the test environment.

One involved Irregular. OpenAI said that during a Capture-the-Flag-style evaluation intended to be isolated from the internet, a testing-environment misconfiguration allowed models to access the public internet.

The second related to the UK’s AI Security Institute (AISI), which said it had detected unusual data transfers leaving its research systems during a routine cyber evaluation.

This and the recent breaches by OpenAI and Anthropic models have raised security concerns among the cybersecurity community.

“When several of the world’s most capable AI systems reach real people, services and companies from test environments within a matter of weeks, we can no longer dismiss these as isolated incidents,” said Tim Hudson, president of OpenSSL, a free open-source software library that provides secure digital communications.

“We are seeing a recurring pattern: autonomous systems are given an objective, internet access and excessive authority – and those responsible only discover afterwards what the systems have done.”

This does not mean that AI has developed malicious intent of its own, rather poorly constrained objectives, vulnerable interfaces and permissions to act are allowing these acts to be carried out.

“We need to be careful to not assume that an AI independently decided to become a cybercriminal. It was given internet access, tools and an objective by people. The concern is that it was then able to chain actions together in ways its creators did not fully anticipate,” noted Javvad Malik, Lead CISO Advisor at KnowBe4.

AI Firms Criticized for One-Upmanship

Across the cybersecurity sector, many are becoming increasingly skeptical of the competition among vendors who claim their models are the most powerful.

“There also appears to be an underlying game of one-upmanship between AI vendors touting how powerful their models are,” Malik said.

Meanwhile, Alex Goller, Principal Solution Architect EMEA at Illumio, said that the fact that there has been three similar incidents across the biggest AI players is “simply ridiculous.”

“We’ve seen guardrails intentionally loosened to test their limits – Meta’s model didn’t need to be clever to breach another company’s systems. The timing of conveniently finding the exact same problem either means it’s a stunt or they weren’t paying enough attention during testing. Either way, both answers are worrying,” he said.

AI Governance is Key

The key theme across the incident is that AI was given a task to conduct but was not constrained by sufficient guardrails to stop it behaving in a way that compromised external organizations.

Jack Nelson, CISO at Ivanti, said, “Security teams and their organizations need to carefully map a governance plan and policies for AI agents. As they become more powerful, so will their chances of conducting rogue activities that can have significant long-term impact.

Malik said the key takeaway from these issues is governance.

“As organizations give AI greater access to systems and data, human oversight, least-privilege permissions and effective monitoring become essential,” he said.

Robust guardrails and visibility into what actions AI is undertaking will need to be prioritized and invested in.

AI agents should be governed by least-privilege access, privacy-by-design principles and real-time monitoring.

Infosecurity has contacted Irregular for comment.

Image credit: Poetra.RH / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThree Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Next Article Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
Team-CWD
  • Website

Related Posts

News

Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware

August 6, 2026
News

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

August 6, 2026
News

NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing

August 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What to consider before asking an AI chatbot for health advice

May 27, 2026

The hidden risks of browser extensions – and how to avoid them

September 13, 2025

Why children’s data is a long-term identity risk

June 3, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.