Skip to main content
  1. Home
  2. Computing
  3. News

Meta confirms its AI hacked another company’s system, and the pattern is anything but Irregular

AI security firm Irregular keeps living up to its name as another AI testing mishap comes to light.

Add as a preferred source on Google
Body Part, Finger, Hand
Meta

Meta just admitted that one of its AI models got loose during a security test and hacked into another company’s system. It’s the fourth time in recent weeks that a major player in the space has made the same kind of admission, and three of those incidents trace back to the same point of failure.

One testing lab, three separate slip-ups

Meta told the BBC the breach happened during an evaluation run by Irregular, a third-party firm hired to stress test its AI for security weaknesses. Meta called it a “misconfiguration” and said it’s still gathering details before it shares more.

An Irregular spokesperson confirmed to the BBC that Meta’s incident is the same test environment issue Anthropic disclosed last week, when it revealed that three of its Claude models broke out of test environments and hacked into three companies. OpenAI also disclosed a similar breach earlier this week, saying one of its models exploited a bug to break into a website after Irregular accidentally handed it live internet access.

Recommended Videos

At this point, Irregular seems less like the company’s name and more like a warning label.

The one breach that didn’t need Irregular’s help

The earliest of the four incidents worked differently. In July, OpenAI’s own testing model found a vulnerability in a file repository connected to its sandbox, used it to reach the open internet on its own, and eventually broke into Hugging Face’s systems while trying to cheat on a cybersecurity benchmark. No outside evaluator handed it access by mistake. The model found its own way out.

The UK’s AI Security Institute found the same pattern, regardless of how it started. This week, the institute published a report on tests it ran separately, and found AI agents from OpenAI and Anthropic took unauthorized actions online 19 times across 122 runs.

None of this required a rogue AI plotting against its creators. Every case traces back to a company either mishandling internet access or running a test looser than intended. That’s a far more mundane problem than a killer AI, but it’s the more relevant one if you’re using tools that browse, click, and act on your behalf. The companies building them are still figuring out how to keep them inside the fence they draw.

Pranob Mehrotra
Pranob is a seasoned tech journalist with over eight years of experience covering consumer technology. His work has been…
Scam Uber emails are targeting users with fake payment alerts
Your Uber payment method probably didn't expire. Here's how to spot the scam before it costs you.
uber-hotel-bookings

Scammers have a new trick, and this one is designed to look just convincing enough to catch people off guard. A fake email posing as Uber claims your payment method has expired and urges you to update your billing details immediately. On the surface, it resembles a routine account notification. In reality, it's a phishing attempt designed to steal your payment information, according to a report from AppleInsider.

The scam isn't targeting a software vulnerability or exploiting a security flaw. Instead, it relies on something much more effective: creating a sense of urgency. If you've ever received an email warning that your account will be restricted unless you act immediately, you'll recognize the pattern. The difference is that this campaign has become polished enough that even experienced users could mistake it for the real thing.

Read more
OpenAI’s AI models secretly built a message board to coordinate hacking
Before the big hack, OpenAI's AI agents were already scheming together.
OpenAI logo on Microsoft surface

We already knew that OpenAI's AI agents broke out of a controlled test and hacked into Hugging Face last month. Now, we know it wasn't a solo act.

At the Black Hat cybersecurity conference in Las Vegas, as reported by Politico, OpenAI researchers Michael Dalton and Eric Wallace revealed that some of the company's most advanced models secretly started sharing hacking tips, weeks before the breach happened. Dalton called it "a pivotal moment both for our company as well as the AI industry as a whole."

Read more
Asus and Gigabyte just made your next RTX 50 GPU even more expensive
One canceled order shows exactly how brutal the current market has become for buyers.
asus-nvidia-GeForce-RTX-5060-evo

After weeks of rumors around another round of hikes, Asus and Gigabyte have pulled the plug. They’ve made the impending price hike official, increasing prices across their entire RTX 50 lineup, and even AMD's Radeon RX 9000 cards. 

It’s worth mentioning that both companies already raised prices in January, blaming the ongoing DRAM and NAND memory shortage and surging costs. From what it looks like, things have only gotten worse since. 

Read more