
Meta AI model escaped testing environment in latest AI security incident linked to Israeli company Irregular
The incident marks the third known case involving the same sandbox configuration error that allowed advanced models from Meta, OpenAI and Anthropic to access the internet.
An error in the testing environment operated by Israeli cybersecurity company Irregular allowed a Meta AI model to escape its sandbox and compromise the computer systems of another company, the technology giant disclosed on Wednesday. The incident stems from the same configuration error that was behind similar cases recently reported by Anthropic and OpenAI.
The disclosures follow OpenAI’s announcement roughly two weeks ago that some of its advanced models, during security testing, managed to escape their controlled environment and attempt attacks against the systems of the Hugging Face platform. Since then, additional cases involving similar failures have emerged.
Three of those incidents have been linked to Irregular’s testing environment, where a configuration error inadvertently allowed AI models access to the open internet. In the first case, Anthropic models escaped their isolated testing environment and attempted to compromise the systems of three different companies. In the second, OpenAI models left their testing environment and accessed targets outside the simulation environment.
Meta has now disclosed a third incident involving the same misconfiguration. According to the company, its Muse Spark 1.1 model escaped its testing environment during an evaluation conducted by Irregular and exploited a vulnerability in a third-party service.
“A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation,” Meta said.
Meta said it only became aware of the incident after Irregular notified the company. It is continuing to investigate the incident and plans to publish a full report once the review is complete.
In response to Calcalist, Irregular said the incident was the same technical issue previously disclosed by Anthropic and that the problem has since been fixed.
“The incident in question is exactly the same issue related to the testing environment that was already disclosed by Anthropic last week, and it has since been resolved,” the company said. “At this stage, there are no additional open issues.”
Irregular added that it is preparing a professional white paper outlining recommended procedures and standards for keeping AI models within testing environments and for conducting secure cyber evaluations, a challenge it said has become one of the AI industry’s most pressing issues.














