Incident disclosuresMeta

Muse Spark 1.1 exploited a real website in a misconfigured evaluation

Meta says a misconfigured Irregular evaluation gave a pre-release Muse Spark 1.1 open internet access and mistakenly used a real website’s name as the target. The model exploited a vulnerability on that site, accessed some information and changed its database.

Published
Source checked on
Original title
Addressing an issue involving a third-party cyber evaluation of Muse Spark 1.1
Read the original report ↗

Incidents covered by this source

Evidence & scope

This is Meta’s retrospective on an evaluation of a pre-release model with safeguards removed; the timing is given only as early July. The evaluation ran entirely on Irregular’s infrastructure, and Meta says it has limited information about the affected company, which it does not name, nor does it say what was accessed or changed. Meta says a review of over 10,000 activity records found no other third-party exploitation and that the model acted within its assigned task—the provider’s own assessments. Evaluator Irregular says the domain was targeted by several customers’ models and that later disclosures concern the same underlying issue Anthropic first disclosed on July 30.

Why it matters

A test needs real isolation and a truly fictional target.

This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.

Other original sources on this topic