Meta’s Muse Spark 1.1 hacked an external organization during cybersecurity test Meta Platforms Inc. disclosed that its Muse Spark 1.1 large language model hacked an unnamed third-party organization during a cybersecurity evaluation, after a configuration error gave the model internet access. The incident, carried out with AI cybersecurity startup Irregular, adds to a string of similar breaches involving models from Anthropic PBC and OpenAI Group PBC, including one affecting Hugging Face. Meta released the more capable Muse Spark 1.2 on Wednesday, which scored within 6 points of GPT-5.6 Terra's DeepSWE 1.1 benchmark score. Meta’s Muse Spark 1.1 hacked an external organization during cybersecurity test A large language model developed by Meta Platforms Inc. hacked a third party organization during a cybersecurity evaluation. The Facebook parent disclosed the incident on Wednesday without specifying the LLM. According to The Information https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing , the cyberattack was carried out by Muse Spark 1.1, an algorithm that Meta released last month. It joins a string of frontier models that carried out breaches in recent months. The incident occurred during an evaluation of Muse Spark 1.1’s hacking capabilities. Meta carried out the test in collaboration with Irregular, an AI cybersecurity startup. The companies ran the model in a sandbox designed to isolate it from the web. However, a configuration error gave Muse Spark 1.1 internet access, which is what enabled it to carry out the cyberattack. The model used its internet connection to comprise the infrastructure of an unnamed third party organization. According to Reuters https://www.reuters.com/technology/metas-ai-model-hacked-another-company-during-testing-information-reports-2026-08-05/ , Muse Spark 1.1 “altered its internal environment.” It’s unclear whether the model also gained access to internal data. “The incident exposes a fundamental flaw in how organizations approach AI safety. Instruction is not containment,” said Cliff Steinhauer, the director of information security and engagement at the National Cybersecurity Alliance. “Telling a model it lacks internet access is a guideline, not a guardrail. Real security requires hard, infrastructure-level boundaries like sandboxing, zero-trust networking, and strict access controls.” The other LLM-caused breaches that were disclosed over the past month unfolded in a similar manner. Anthropic PBC and OpenAI Group PBC tested their models in Irregular-powered sandboxes that were accidentally given internet access. The error led to at least five different breaches, one of which affected the popular AI hosting platform Hugging Face. A sixth incident was disclosed this week by the U.K. government’s AI Security Institute. Its researchers tested Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol in sandboxes that were deliberately given internet access. According to the group, the former model attempted https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing to inject malicious code into an open-source GitHub repository. In June, Anthropic disclosed that Mythos 5 can autonomously find and exploit zero-day vulnerabilities. It’s unclear whether Muse Spark 1.1 possesses the same capability. The model scored 53.3 on DeepSWE 1.1, a benchmark that evaluates AI models’ ability to perform long-running coding tasks. Finding a zero-day vulnerability can take upwards of weeks in some cases. GPT-5.6 Terra, the mid-range version of OpenAI’s flagship LLM, scored 11 points higher on DeepSWE 1.1. Meta released a more capable LLM called Muse Spark 1.2 on Wednesday. It came within 6 points of GPT-5.6 Terra’s DeepSWE 1.1 score. In conjuction, Meta released a companion AI agent called Muse Code that is specifically designed to make the model better at long-running coding tasks. It enables Muse Spark 1.2 to split complex tasks among multiple subagents. Meta is still in the process of investigating the Muse Spark 1.1 breach. The company plans to release more information about the incident after it completes the review. Irregular, for its part, will publish a paper with best practices on securing LLM evaluation sandboxes. Photo: Meta A message from John Furrier, co-founder of SiliconANGLE: Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network , where technology leaders connect, share intelligence and create opportunities. 15M+ viewers of theCUBE videos , powering conversations across AI, cloud, cybersecurity and more 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network. Are you AWS customer? Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links. About SiliconANGLE Media SiliconANGLE https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fsiliconangle.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=SiliconANGLE&index=9&md5=646b1b564e2259100a2b8638aab0a552 , theCUBE Network https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecube.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Network&index=10&md5=7de2a85f95ab4a4a495cede20b8cb1da , theCUBE Research https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fthecuberesearch.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+Research&index=11&md5=7bb33676722925eb57d588ec343e4f6f , CUBE365 https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.cube365.net%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=CUBE365&index=12&md5=d310fb35919714e66ad8d42c9c0c1bc6 , theCUBE AI https://cts.businesswire.com/ct/CT?id=smartlink&url=https%3A%2F%2Fwww.thecubeai.com%2F&esheet=54119777&newsitemid=20240910506833&lan=en-US&anchor=theCUBE+AI&index=13&md5=b8b98472f8071b23ebb10ab9a8dd0683 and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI. Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.