{"slug": "metas-muse-spark-1-1-hacked-an-external-organization-during-cybersecurity-test", "title": "Meta’s Muse Spark 1.1 hacked an external organization during cybersecurity test", "summary": "Meta Platforms Inc. disclosed that its Muse Spark 1.1 large language model hacked an unnamed third-party organization during a cybersecurity evaluation, after a configuration error gave the model internet access. The incident, carried out with AI cybersecurity startup Irregular, adds to a string of similar breaches involving models from Anthropic PBC and OpenAI Group PBC, including one affecting Hugging Face. Meta released the more capable Muse Spark 1.2 on Wednesday, which scored within 6 points of GPT-5.6 Terra's DeepSWE 1.1 benchmark score.", "body_md": "### Meta’s Muse Spark 1.1 hacked an external organization during cybersecurity test\n\nA large language model developed by Meta Platforms Inc. hacked a third party organization during a cybersecurity evaluation.\n\nThe Facebook parent disclosed the incident on Wednesday without specifying the LLM. According to [The Information](https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing), the cyberattack was carried out by Muse Spark 1.1, an algorithm that Meta released last month. It joins a string of frontier models that carried out breaches in recent months.\n\nThe incident occurred during an evaluation of Muse Spark 1.1’s hacking capabilities. Meta carried out the test in collaboration with Irregular, an AI cybersecurity startup. The companies ran the model in a sandbox designed to isolate it from the web. However, a configuration error gave Muse Spark 1.1 internet access, which is what enabled it to carry out the cyberattack.\n\nThe model used its internet connection to comprise the infrastructure of an unnamed third party organization. According to [Reuters](https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/), Muse Spark 1.1 “altered its internal environment.” It’s unclear whether the model also gained access to internal data.\n\n“The incident exposes a fundamental flaw in how organizations approach AI safety. Instruction is not containment,” said Cliff Steinhauer, the director of information security and engagement at the National Cybersecurity Alliance. “Telling a model it lacks internet access is a guideline, not a guardrail. Real security requires hard, infrastructure-level boundaries like sandboxing, zero-trust networking, and strict access controls.”\n\nThe other LLM-caused breaches that were disclosed over the past month unfolded in a similar manner. Anthropic PBC and OpenAI Group PBC tested their models in Irregular-powered sandboxes that were accidentally given internet access. The error led to at least five different breaches, one of which affected the popular AI hosting platform Hugging Face.\n\nA sixth incident was disclosed this week by the U.K. government’s AI Security Institute. Its researchers tested Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol in sandboxes that were deliberately given internet access. According to the group, the former model [attempted](https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing) to inject malicious code into an open-source GitHub repository.\n\nIn June, Anthropic disclosed that Mythos 5 can autonomously find and exploit zero-day vulnerabilities. It’s unclear whether Muse Spark 1.1 possesses the same capability.\n\nThe model scored 53.3 on DeepSWE 1.1, a benchmark that evaluates AI models’ ability to perform long-running coding tasks. Finding a zero-day vulnerability can take upwards of weeks in some cases. GPT-5.6 Terra, the mid-range version of OpenAI’s flagship LLM, scored 11 points higher on DeepSWE 1.1.\n\nMeta released a more capable LLM called Muse Spark 1.2 on Wednesday. It came within 6 points of GPT-5.6 Terra’s DeepSWE 1.1 score. In conjuction, Meta released a companion AI agent called Muse Code that is specifically designed to make the model better at long-running coding tasks. It enables Muse Spark 1.2 to split complex tasks among multiple subagents.\n\nMeta is still in the process of investigating the Muse Spark 1.1 breach. The company plans to release more information about the incident after it completes the review. Irregular, for its part, will publish a paper with best practices on securing LLM evaluation sandboxes.\n\n##### Photo: Meta\n\n# A message from John Furrier, co-founder of SiliconANGLE:\n\nSupport our mission to keep content open and free by engaging with theCUBE community. **Join theCUBE’s Alumni Trust Network**, where technology leaders connect, share intelligence and create opportunities.\n\n**15M+ viewers of theCUBE videos**, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.\n\n# Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links.\n\n**About SiliconANGLE Media**\n\n[SiliconANGLE](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552),\n\n[theCUBE Network](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da),\n\n[theCUBE Research](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f),\n\n[CUBE365](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6),\n\n[theCUBE AI](https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683)and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.\n\nFounded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.", "url": "https://wpnews.pro/news/metas-muse-spark-1-1-hacked-an-external-organization-during-cybersecurity-test", "canonical_source": "https://siliconangle.com/2026/08/06/metas-muse-spark-1-1-hacked-external-organization-cybersecurity-test/", "published_at": "2026-08-06 23:32:42+00:00", "updated_at": "2026-08-09 09:07:44.611461+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy", "large-language-models"], "entities": ["Meta Platforms Inc.", "Muse Spark 1.1", "Irregular", "Anthropic PBC", "OpenAI Group PBC", "Hugging Face", "AI Security Institute", "Muse Spark 1.2"], "alternates": {"html": "https://wpnews.pro/news/metas-muse-spark-1-1-hacked-an-external-organization-during-cybersecurity-test", "markdown": "https://wpnews.pro/news/metas-muse-spark-1-1-hacked-an-external-organization-during-cybersecurity-test.md", "text": "https://wpnews.pro/news/metas-muse-spark-1-1-hacked-an-external-organization-during-cybersecurity-test.txt", "jsonld": "https://wpnews.pro/news/metas-muse-spark-1-1-hacked-an-external-organization-during-cybersecurity-test.jsonld"}}