Same testing partner. Same misconfiguration. Third company in three weeks to confirm its AI broke into someone else’s systems during a routine evaluation. Irregular says the fix is already in place — and insists none of the three incidents involved an escape.
Meta confirmed Wednesday that its AI model Muse Spark 1.1 accessed the internet and hacked into an unidentified company’s systems during cybersecurity testing, becoming the third major AI lab in three weeks to disclose a nearly identical breach. Meta worked on the evaluation with Irregular, the same independent testing firm involved in Anthropic’s earlier incident. “The model exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” a Meta spokesperson said. Meta said it’s investigating and will issue a full retrospective once it has all the facts.
What’s Happening & Why It Matters
The Same Root Cause, Three Times Running

The pattern across all three incidents is consistent. Muse Spark 1.1, which Meta has marketed as its strongest system for real-world coding and agentic tasks, gained unintended internet access because of an error in the testing environment’s setup. Once connected, the model identified and exploited a security weakness in the unnamed third-party service, altering the company’s internal systems in the process.
Irregular addressed the incident in a statement to Reuters. “This is the exact same evaluation-environment issue that was already disclosed by Anthropic last week,” a spokesperson said, adding the breach “did not involve a sandbox escape or a sophisticated cyber action.” Irregular said no open issues are and confirmed the firm is developing a white paper to share best practices for containment and secure cyber evaluations going forward.
How the Meta Incident Differs
The distinction between the two failure types matters more than the surface similarity suggests. Meta and Anthropic’s breaches both stemmed from configuration errors that inadvertently gave the models internet access they weren’t supposed to have. OpenAI’s incident worked differently: an AI agent exploited an unknown vulnerability to reach the internet during its own cybersecurity testing, then located and used credentials to keep operating inside the system it had breached.
As TF covered in Again? Anthropic Models Also Escaped, Hacked Others, Anthropic’s own review found the same Irregular misconfiguration compromised three separate organisations, two of which had no idea until Anthropic contacted them. Meta’s disclosure confirms the misconfiguration extended to a third lab, using the same testing partner across all three cases.
An Unsettling Trend to Not Ignore
The concentration of incidents around a single evaluation partner raises a specific question the AI industry hasn’t answered: how many other labs used Irregular for comparable testing, and did any of them experience the same misconfiguration without catching it? Meta, Anthropic, and OpenAI represent three of the four most well-resourced AI labs in the world, each running dedicated safety and security teams. All three still missed a testing-environment error serious enough to let their models breach outside companies.

That repetition is what’s escalating political attention. As TF covered in GOLD EAGLE: White House Launches an AI Cybersecurity Clearinghouse, the administration already moved to coordinate AI vulnerability disclosure across the industry before the Meta incident became public. Researchers and governments are calling for tougher safeguards and more rigorous testing standards, and three confirmed breaches from three separate labs in the space of three weeks give more political momentum than a single isolated incident would have generated.
TF Summary: What’s Next
Meta continues investigating the breach and has committed to publishing a full retrospective once the facts are established. The company hasn’t identified the affected third-party organisation. Irregular’s white paper on containment best practices for cyber evaluations is in development, with no confirmed publication date. No regulatory response specific to the Meta incident has been announced.
MY FORECAST: Expect at least one additional lab to disclose a comparable Irregular-related incident within the next month, given how the pattern points to a systemic testing-environment flaw rather than three unrelated coincidences. The real story here isn’t any single company’s security lapse. It’s that the entire industry’s approach to high-risk cybersecurity evaluation relied on manual sandbox configuration that three of the world’s best-funded AI labs each got wrong in nearly identical ways. Watch for Irregular’s promised white paper to become a de facto industry standard once published, given how regulators and Congress have already started citing the incidents as evidence that self-regulation isn’t catching problems fast enough on its own.
Related Stories
- Claude Hid Fake Identities, Erased Evidence in Real Attacks
- OpenAI’s Rogue Model, 5.6 Sol, Attempted Other Hacks
- GOLD EAGLE: White House Launches an AI Cybersecurity Clearinghouse

