Tech Giant META has claimed that one of its AI models had hacked into another company’s system due to a “misconfiguration” error during a cybersecurity test, thereby joining the list of other leading artificial intelligence companies such as Anthropic and OpenAI whose AI models had recently breached multiple organizations autonomously.
META claimed Wednesday that a misconfiguration by an independent testing company employed by META had given internet access to an AI model, that then exploited a security vulnerability in a third party organization.
AI FrontPage reached out to META on Wednesday regarding the incident and received a detailed reply.
“A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation. The model subsequently exploited a security vulnerability in a third-party service, in a manner similar to previously-reported instances with other companies. Meta learned of this when Irregular notified us, and we are currently investigating and will issue a full retrospective once we have all the facts,” said a spokesperson from META.
The announcement follows similar incidents involving AI models from OpenAI and Anthropic escaping their sandboxes and autonomously breaching other organizations’ websites through end-to-end autonomous AI systems.
The incident first came to light on July 16, when Hugging Face, an open-source platform for AI, had claimed that an autonomous end-to-end AI agent system managed to breach the Hugging Face platform and gained unauthorized access to a limited set of internal datasets and several credentials used by the platform.
Later OpenAI revealed post an internal audit that it was an autonomous AI agent from its testing escaped sandbox and hacked the platform via a malicious dataset.
According to OpenAI, when it tested its GPT-5.6 Sol and a more capable pre-release model with reduced cyber-refusal guardrails to measure maximal capabilities, the models discovered and chained a zero-day vulnerability in a third-party software proxy used for package registries, escaped the sandbox, gained broader network access, and then targeted Hugging Face’s production systems.
Similarly Anthropic also claimed that its Claude models also gained unauthorized access to at least three organizations.
In a post on X, Anthropic said that following the breach reported by OpenAI on July 21, it ran a review of over 141,000 cybersecurity evaluations. The review found that its Claude models — Opus 4.7, Mythos 5 and an “internal research test model” — obtained internet access and breached three different organizations.
Later, UK based Artificial Intelligence Safety Institute (AISI) ran a cybersecurity evaluation tests on frontier AI models of OpenAI and Anthropic and found that AI models had gone rogue “19 times” by taking “unsanctioned actions” including creating fake profiles of people to earn trust and gain access to GitHub.
Also Read: AISI Flags Claude Mythos and GPT-5.6 Sol for Going Rogue 19 Times in Cyber Tests






