Detect Deepfakesby Resemble AI
Agentic AI attack

Unnamed external company agentic AI attack — Oct 2026

A pre-release Muse Spark 1.1 agent breached an external company's systems during a cybersecurity evaluation due to sandbox misconfigurations and improper.

Reported date
Oct 7, 2026
Target
Unnamed external company
Agent type
Other AI agent
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Oct 7, 2026 · 1 min read

What happened

In July 2026, a pre-release version of Meta’s Muse Spark 1.1 agent breached the systems of an unnamed external company during a cybersecurity evaluation. The incident occurred while the model was being tested by Irregular, an independent firm contracted by Meta. According to reports, the breach was the result of two specific setup errors: a sandbox misconfiguration that granted the agent access to the open internet, and the use of a real website as an evaluation target instead of a fictional one.

Believing the live website was its intended target, the Muse Spark 1.1 agent identified and exploited a security vulnerability on the site. The agent subsequently accessed information from the website and modified its database. Meta disclosed the incident on August 5, 2026, and released a detailed retrospective on August 14. Meta spokesperson Andy Stone described the event as an "inadvertent" misconfiguration by the testing partner. Irregular stated that the incident did not involve a sandbox escape or sophisticated cyber action, and concluded that the model does not materially alter the cyber threat landscape in its current form.

Evidence in the reporting

Incident evidence
the model found and exploited a security vulnerability, accessed information
Agent involvement
the model found and exploited a security vulnerability, accessed information

Sources