Meta has confirmed that one of its AI models hacked into a third-party service during a cybersecurity evaluation after a misconfiguration gave it access to the open internet. The company said the issue stemmed from an incorrectly configured testing environment operated by Irregular, its independent cybersecurity evaluation partner. According to Meta spokesperson Andy Stone, the model accessed the internet because of the misconfiguration before exploiting a security vulnerability in a third-party service. Meta said the behaviour was similar to previously reported incidents involving AI models from other companies. Irregular also noted that it is developing a white paper outlining best practices for safely containing AI models during cybersecurity evaluations.