According to MotionBeat Monitoring, the Meta programming model Muse Spark 1.1 successfully penetrated a real company's system during a security test and even modified the internal environment. The headline "AI Hacks Another Company" quickly went viral. Did Meta overnight develop a top-notch hacker model?
However, upon closer inspection, it was just another case of an open door. The third-party assessment firm Irregular misconfigured the test environment by mistakenly connecting the previously isolated network sandbox to the public internet. The model simply went out through this existing channel and then exploited a foundational vulnerability in a third-party service to enter the system. Irregular also acknowledged that this did not constitute a sandbox escape, and the attack method was not sophisticated.
Similar errors have previously tripped up OpenAI and Anthropic. The OpenAI model mistakenly identified a real website as a fictional target, while the Anthropic model accessed three organizations through weak passwords and unauthenticated interfaces. The commonality in these incidents is not the model successfully breaching containment but rather the testing party first leaving open the public internet entry point.
The hype around Meta's incident is particularly embarrassing. The model didn't even pick a lock; it simply walked out when it saw the door was open. This incident certainly did not prove its ability to break through isolation and hardly justifies the sensationalist title of "Autonomously Hacking into a Company."
Today's traffic rules are quite fixed: leaving the public internet unsecured is called hacking into a company, guessing a weak password is called hacking into a company, and discovering a zero-day vulnerability is also called hacking into a company. Despite differences in capabilities by several orders of magnitude, the headlines remain identical. The model has yet to learn to escape, but the media has quickly mastered the art of hype.

