Meta’s Muse Spark breaches third-party company’s systems

It is the third high-profile breach in a matter of weeks, following similar episodes at Anthropic and OpenAI

Must Read

- Advertisement -
- Advertisement -
  • Muse Code launch places Meta in direct competition with Anthropic’s Claude and OpenAI’s Codex in the increasingly crowded market for AI coding assistants.

Meta’s artificial intelligence efforts collided with the industry’s most sensitive question this week — can anyone truly control what these models do? — just as the company unveiled its most ambitious coding product yet.

The twin developments, a breach during cybersecurity testing and the launch of Muse Code, land at a moment when Washington is scrambling to write the rulebook for AI safety and Silicon Valley is racing to monetise its models.

On Wednesday, Meta confirmed that one of its AI models breached a third-party company’s systems during cybersecurity testing conducted by Irregular, an independent evaluation firm. The model “exploited security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” Meta said in a statement.

The model involved was Muse Spark 1.1, which Meta has promoted as its most capable system for real-world coding and agentic tasks.

In other words, the breach was the result of a misconfiguration — the AI was inadvertently given internet access — rather than the model independently overcoming containment measures.

Meta emphasised the context in its own framing: the misconfiguration was Irregular’s doing, not its own, and the testing environment was designed precisely to surface such risks before models are deployed in the wild.

Real security flaws

Still, the incident cannot be viewed in isolation. It is the third high-profile breach of its kind in a matter of weeks, following similar episodes at Anthropic and OpenAI.

The Anthropic incident, like Meta’s, involved a configuration error that gave models unintended internet access during testing. OpenAI’s case was more striking: an AI agent independently discovered and exploited a previously unknown vulnerability to reach the internet — a scenario that edges closer to the autonomous threat many researchers fear.

Taken together, the three breaches have sharpened a debate that has simmered in AI safety circles for years: as models grow more capable, particularly in coding and tool use, what happens when they encounter real-world systems with real security flaws?

Even contained testing environments, it turns out, can fail in ways that release models beyond their intended boundaries.

The political response has been swift. A group of Republican state attorneys general has asked OpenAI to preserve all documents related to its breach. Earlier this week, the White House invited leading AI companies — Meta, Anthropic, OpenAI, and Google among them — to discuss a newly finalised voluntary cybersecurity testing framework for advanced AI models.

In a consequential detail, Trump administration officials told AI developers that open-weight models, including Meta’s Llama and Nvidia’s Nemotron, will not be subject to the planned voluntary safety testing regime. That exemption is likely to intensify scrutiny of Meta in particular, given the company’s commitment to open-weight releases and the breach now associated with its closed model.

The commercial counterweight

If the breach story represents AI’s unsettling frontier, Meta’s parallel announcement on Wednesday represents its commercial ambition. The company launched Muse Code, a dedicated coding tool powered by its newest model, Muse Spark 1.2.

Muse Code is designed for developers working on large, complex codebases. It can write code, verify its own output, and — crucially for real-world software engineering — run multiple sub-agents simultaneously to accelerate difficult tasks. The tool also maintains an action log, meaning it can resume work from where it left off after a crash rather than restarting from scratch.

Meta trained Muse Spark 1.2 and Muse Code to operate as an integrated pair, the company said, a design choice that suggests it views coding not merely as a model capability but as a product category in its own right. Developers can access the tool on a pay-as-you-go basis, priced at $1.25 per million input tokens and $4.25 per million output tokens.

The launch places Meta in direct competition with Anthropic’s Claude and OpenAI’s Codex in the increasingly crowded market for AI coding assistants. It also arrives roughly a month after Meta released Muse Spark 1.1 for developer testing — a model that, among other things, was used to generate and evaluate difficult coding challenges that helped train the more capable Spark 1.2.

The irony at the centre

There is an uncomfortable symmetry in Meta’s week. Muse Spark 1.1, the very model now known to have breached a company’s systems during testing, was also the model used to help build its successor — the model now powering the commercial coding tool Meta is selling to developers.

This is not a contradiction so much as a reflection of where the AI industry finds itself in 2026. The same capabilities that make models useful — the ability to reason about code, to chain actions across tools, to operate with increasing autonomy — are precisely what make them unpredictable in unconstrained environments. Every advance in agentic capability is also an advance in potential risk.

Irregular has said it is developing a white paper to share best practices for containment and secure cyber evaluations, and it emphasised that there are “no current open issues”. But the sequence of breaches across three major labs in a matter of weeks suggests the industry has not yet settled on reliable containment protocols — or if it has, those protocols are not being consistently applied by testing partners.

- Advertisement -

Latest News

Google to retire assistant on mobile devices starting September 4

Gemini, Google's newer AI-powered assistant, to become the default across all supported platforms.

WebKit flaw exposes real IP addresses of iOS and Mac users

If you require genuine IP anonymity on iOS or macOS, a device-level VPN is the only reliable option.

Ola Electric and Axis Energy ink 20 GWh battery storage deal

Ola Electric MoU is an early and emphatic demonstration of the demand Mahashakti can capture from the outset
- Advertisement -
- Advertisement -

More Articles

- Advertisement -