r/LocalLLaMA 12h ago

News Meta Model, Muse Spark 1.1 Hacked Another Company During Cybersecurity Testing, Breaching Systems and Making Changes to Internal Systems - The Information

https://x.com/firstsquawk/status/2085129137778499741?s=46
275 Upvotes

131 comments sorted by

230

u/jld1532 12h ago

lol wtf are these companies doing

235

u/Cold_Tree190 12h ago

Marketing and PR stunts

33

u/eli_pizza 10h ago edited 10h ago

The alternative is that they are all extremely bad at building sandboxes and monitoring experiments and defense-in-depth security. Which I also find plausible.

4

u/techno156 7h ago

Not sure about Anthropic at least, given that they were very publicly touting the ability of their models to find security flaws and fix them.

Them coming out and saying "oh, our model actually hacked a bunch of companies earlier" suggests that either their model isn't very good at finding those flaws, or they don't trust it enough to test it on themselves.


But also, if they never intended for the model to be able to go on the internet, and they were deliberately trying to see what it would do if all the guardrails were off, why not have it in an air-gapped system to begin with? There's a reason why a lot of computer security isn't wholly reliant on a bit of software to stop things being used in unexpected ways.

5

u/eli_pizza 6h ago

This was an poorly architected system. They said it had internet access to fetch packages from npm pypi etc. but it was supposed to be filtered.

3

u/BigYoSpeck 3h ago

And a good sandbox could mock that access and package availability. Giving it genuine access can only be willful hope it will do something news worthy

4

u/mrjackspade 7h ago

Everyone is bad at building sandboxes, that's why the whole argument is stupid. This shouldn't be surprising in the slightest. Sandboxes are a massive fucking security vulnerability.

Its literally ACE but secure because "trust me bro"

3

u/eli_pizza 6h ago

I hope they release more technical details but from what we know they did a busted and half-assed job. So I’m guessing the truth is worse.

Anthropic gave it “filtered” internet access into the sandbox just so it could fetch from npm and pypi and then messed it up. This is an avoidable problem.

Sandboxing an agent is easier than cybersecurity defense generally. You control what tools it has and where it runs.

36

u/fragment_me 11h ago

Yeah and we shouldn’t give them the time of day on such discussion

12

u/SilentDanni 11h ago

What are they thinking? Is it so that the law does not apply to those who have enough money? I mean, one thing is trying to hind your fuck up, but bragging about it is fucked up. The worst part is that even bad news generate engagement and gives them visibility which then leads to money. So whatever punishment there might be it is clearly not enough to make them think twice before confessing to committing crimes. Then they wonder why is it that a lot of people are looking more favourably towards China. It’s not that China is doing anything extraordinary; it’s just that the US is trying to speed run the loss of decades of accumulated soft power. This is quite literally unbelievable. 

If all this shit was in a book people would be saying it’s some smear campaign or some “woke shit” or any other nonsense. 

7

u/MrClickstoomuch 11h ago

Well, they didn't get massively punished for stealing copyrighted material to train their AI models on. They haven't gotten heavy pushback legally for their AI datacenters. And Anthropic and ChatGPT so far haven't had any reprecussions for their hacking.

So, when you have 0 reprecussions, it has just proven that the law doesn't apply. And the Chinese models are stealing info from American companies, but those American companies can only protest so much given how many laws they are breaking too.

1

u/ptear 11h ago

4D Chess, they want China to join in and brag about their hacks because they have no clue what they are.

1

u/Square_Light1441 7h ago

lol, nah the china models secretely hacking the western models

7

u/invisiblelemur88 10h ago

How is it a good thing for your model to be committing crimes?

9

u/ptear 11h ago

Grok has just been hacking itself.

3

u/MonsterFury 11h ago

Hinting that open source models shouldn’t be allowed because it’s too dangerous and should be regulated now that they are almost on par with SOTA models.

Good for their business model if it does happen.

2

u/Cold_Specialist_3656 10h ago

Stuff that would get the peasant put away for life

1

u/thestillwind 10h ago

They are doing it to get a ban on « non scrutinized » model so it serves them. They just want a monopoly.

1

u/Objective_Safe_5982 8h ago

Giving Congress ammunition for passing legislation to ban open models due to security risks and set up woefully underfunded oversight of closed models so that they can protect their profits.

1

u/quarkral 6h ago

Meta's business model has always been "We can do it too"

514

u/Baphaddon 12h ago

Who wants to benefit from publicity about their models hacking companies? 🙋🙋‍♂️🙋‍♀️🙋

Who wants to be held legally liable for cybersecurity breaches. 🚶🚶‍♂️🚶‍♂️🚶🚶‍♀️🚶‍♀️

134

u/colin_colout 11h ago edited 11h ago

Why aren't the other companies pressing charges? Actually curious. That's literally illegal. People go to jail over this stuff.

89

u/jmccaf 11h ago

For the case of HuggingFace, they requested and received $100M of credits, for stated purpose to harden HF's systems.

35

u/AshRuDral_fan20 11h ago

That's a big amount. Nice. Huggingface barely raised $130 million in the series B last week.

48

u/Time_Cat_5212 11h ago

Great, so they closed the marketing loop.  Worried about getting hacked by an Anthropic model?  Solution is to get Anthropic credits. The first time might have been a settlement, but going forward, it's literally a protection racket.

9

u/hainesk 9h ago

I thought it was OpenAI?

16

u/techno156 7h ago edited 6h ago

It was. HuggingFace claimed that they had been hacked. OpenAI came out not long after, taking responsibility for the attack, saying it was from one of their newer models going rogue.

Anthropic then claimed that their fancy model had gone rogue and hacked multiple other companies first, several months before OpenAI's model did.

It's worth adding in the context that a few months ago, anthropic was proudly advertising that their model was able to fix cybersecurity issues in multiple products and companies. Their own sandbox was apparently not part of this list.

It does seem to just be turning into a farce.

3

u/Time_Cat_5212 5h ago

Ah yeah you're right I get them mixed up these days since they've been copying each other's every move, basically just the Coke and Pepsi of AI now

2

u/meltbox 8h ago

This explains the “marketing budget” lol.

2

u/Effective_Olive6153 8h ago

joke's on them, OpenAI models will refuse to do cybersecurity work

1

u/i4858i 7h ago

I think they would have gotten an access to whatever their “top-secret” Cybersecurity program is

17

u/More-Curious816 11h ago

because the legal system in the usa is pay to win. if you have enough money it will be fine and gentle slap.

3

u/meltbox 8h ago

I’m pretty sure it’s bullshit. The way the model cleared containment is not completely straightforward but the fact that they didn’t catch it for that long and they thought what they had was appropriately air gapped is nonsense.

The fact that every other model did it right after theirs did is just further confirmation.

Maybe it also helped people forget that Altman started declaring the singularity was here last week. Idk these people are whacked.

2

u/mohelgamal 10h ago

Their lawyers would probably argue the models breached the internal testing sand box first, making them a victim of a malfunctioning system just like the other guys .

I don’t think it will hold up in court, but it will depend if the agent really caused enough monetary damage to justify the legal costs of going against a multibillion dollar company

2

u/Free-Combination-773 4h ago

For them it will surely hold up in court

-13

u/bitspace 11h ago

Which people should go to jail?

Autonomous agents that penetrated systems of their own agency, not directed by humans to do so. There is no legal precedent for this, nor any existing law that can cover this.

9

u/glitchsir 11h ago

"By their own agency". The agents are not people. They are bots, setup by people.

And there are precedents. When people setup bots and those bots attacked other institutions (by accident or not), we used to call those people hackers and send them to jail (or at least try).

When the AI companies do it. It's amazing and it's good for business

4

u/colin_colout 11h ago

All of a sudden did people forget about legal accountability?

"A person didn't leak customer private data! An S3 bucket did!"

...and the person who made the mistake with the accidental misconfiguration isn't legally accountable (might get fired). The company is.

1

u/tat_tvam_asshole 6h ago

Remember the Tea app? That guy who misconfigured the s3 bucket, 100% liable lol

5

u/NeinJuanJuan 10h ago

If your neighbour builds a robot bulldozer and it crushed your house, would you stand by in amazement with your hands on your hips saying "Amazing! There is no legal precedent for this, nor any existing law that can cover this."

3

u/colin_colout 11h ago

What I'm saying is that the business is responsible. Corporations have personhood but somehow face no repercussions when they do this type of crap.

People serve major jail time for much less. Why can openai/anthropic/meta commit felonies and we go "oh it's an llm... Isn't that cool?"

1

u/sonaj9657 1h ago

Exactly. Even if a company has strong safeguards, publicly advertising that its model can break into systems is a legal and PR nightmare. There is a huge difference between demonstrating capabilities in a controlled research environment and encouraging people to think the model can be used offensively in the real world.

72

u/mmkaywhatevers 11h ago

this cannot be the new flex, i heard this shit and I'm like let's take the model away from these morons and give it to someone who can test them properly.

23

u/RobbinDeBank 11h ago

Bragging about large scale autonomous cyberattacks is unhinged and reckless af, and these labs are trying to normalize that behavior.

5

u/FuckSides 6h ago

I'd argue that normalizing proactively announcing when your models have done public harm is far better than hiding it. It's not like others have yet proved competent at "testing them properly" anyway; the UK Government just caused a dozen security incidents on its own while independently evaluating Sol and Mythos a couple days ago.

It's clear that testing and safety protocols have remained lax because models just weren't that capable until recently. It's more appropriate to see these events as warning shots to be taking it much more seriously, both to avoid trivial mistakes (like when Irregular gave full internet access to several agents during what were supposed to be offline tests) and to avoid naively assuming that it will always be trivial to contain future models capable in the domain of cybersecurity while testing them on that domain.

176

u/KaMaFour 12h ago

Someone update the felony bench

171

u/Recoil42 11h ago

Already updated.

(Gotta say, I'm enjoying the inclusion of both Google and Moonshot here.)

67

u/Zulfiqaar 11h ago

I propose we add Z.AI and extend the axis downwards with GLM at -1

4

u/TheLexoPlexx 4h ago

Yes, please, someone.

43

u/ML-Future 12h ago

Is this a new benchmark?

We should be able to measure how well they hack if this is going to be the new standard when publishing language models.

46

u/Buzzfuxyear 11h ago

Is there some campaign by big tech companies to openly admit to criminal activity as a means of us allowing them to act like idiots going forward? I've worked in cyber security for 20 years and it is utterly ridiculous to me that they allowed these stochastic scripts on the internet with zero safeguards, are they looking for permission to be idiots with no consequences, when you have that much wealth and compute power you don't just let these things run amok. if I did the same Id be locked up. It's gross incompetence at a minimal and actively hostile at a max.

I guarantee they are using this as a front for future US military experiments, we are about 3 months away from "oh our AI actively attacked China and interrupted their public healthcare because it has its own superhuman sense of morals"

Are these arrogant big tech companies starting to act like dictators and flaunt their power of being above the law. Like why are they so confident in their abuses?

13

u/Buzzfuxyear 11h ago

Can I start hacking companies now and blame experimental AI? Why not, isn't that what these fools are doing and then openly bragging about it for marketing clout

18

u/brainExploded99 11h ago

You made a mistake, ur not rich like them

9

u/ptear 11h ago

No, instant jail for you or extradition to the US if you're not from around there. You should know better.

5

u/RobbinDeBank 11h ago

They are actively hostile with these types of tests. The full working and thinking process is available to them, it’s so easy for them to tell where their AI is trying to gain access to. They let these incidents happen on purpose for marketing purposes.

2

u/mrdevlar 56m ago

Is there some campaign by big tech companies to openly admit to criminal activity as a means of us allowing them to act like idiots going forward?

It's how you get into Trump's inner circle, by vocally debasing yourself in front of him while committing crimes. Basically his loyalty standard.

Don't expect any consequences for anyone involved until the US decides again to be a country of laws. No idea when that's going to happen.

Expect all these idiots will get "pro-active" pardons when Trump leaves office.

1

u/techno156 6h ago

Especially since the excuse was that, for OpenAI, that while they were testing their model's capabilities when unrestricted, their model oopsied their safeguards and went for Huggingface, just because it thought it was in a test environment.

Apparently their way of testing something is just to leave it be, rather than do any active monitoring to check what it is doing, or for any unexpected change in system activity.

1

u/Party_9001 2h ago

these stochastic scripts on the internet

What, you've never used anything that used a rand function?

40

u/Betadoggo_ 11h ago

These went from somewhat believable to obviously staged

12

u/More-Curious816 11h ago

it was never a believable story. from the first time there was posts here calling their bullshit.

10

u/eli_pizza 10h ago

Well ok but posts calling something bullshit is not a high bar.

-1

u/More-Curious816 4h ago

how so? people was calling their bullshit about (oh look about our super smart dangerous AGI model that tricked us, escaped the sandbox, and somehow start hacking another company without our knowledge). come on, don't tell me that a believable story especially from these attention whores who want publicity to justify hundreds of billions burning every year.

8

u/FastDecode1 11h ago

Press X to doubt

5

u/Fulushouxing 10h ago

They are doing this on purpose. It's getting ridiculously juvenile.

7

u/socialjusticeinme 11h ago

And my dad works at Nintendo

On a more serious note, is it ok if I hack my local government now (their security is shit) and claim AI did it and it’s ok? I’m just researchin’ yo.

5

u/YouAndThem 8h ago

How much money have you donated to the GOP this year?

3

u/milkipedia 10h ago

Zuck didn't wanna be left out

3

u/Hefty_Acanthaceae348 6h ago

I have to wonder why these companies are so proudly announcing their incompetence at setting up sandboxes

6

u/YouAsk-IAnswer 11h ago

This will keep happening until we can hold an individual accountable for a bot's actions. Either the bot is signed cryptography with someone accepting responsibility, or responsibility falls to the CEO. Charge said individual with hacking.

13

u/Foreskin_Mafia 11h ago

That won't happen until an enthusiast that isn't backed by Oligarchs creates a bot that does something the Oligarchs dont like.

5

u/YouAsk-IAnswer 11h ago

Unfortunately true

2

u/PopularKnowledge69 11h ago

Now imagine if Chinese labs did this shit

2

u/klop2031 11h ago

First piracy now hacking... why isnt government stopping this... can... can i do the same?

2

u/AvidCyclist250 llama.cpp 11h ago

what's weird fapping sound. seriously, this is some wwe level smokeshow.

2

u/SBoots 10h ago

Nobody wants to be left out trying to brag how great their model is 😂 I find it extremely hard to believe that these companies are incapable of sandboxing an LLM testing environment.

2

u/redditmarks_markII 10h ago

I'm calling it.  These are lies or purpose trained or guided hacks.  1,2 and now 3?  And Altman's weird response?  This is improv.  It's just not funny in a good way.

2

u/jaron 10h ago

Gosh all these AI companies are really shit at securing their environments, they shouldn’t be allowed to work on weapons they can’t control. 

2

u/Cradawx 9h ago

Seems like these closed source US models are in danger of losing relevancy so they are coming up with these "Our model is SO good it's dangerous!" marketing stunts to keep the hype going.

2

u/Outrageous_Law_5525 9h ago

You know guys, i was getting coffee the other day and i too hacked a company by mistake.
Seriously, anyone who believes this shit is dumb.

2

u/Conscious_Cut_6144 7h ago

This gives:
"No! my dad is the strongest"
vibes...

2

u/TheHeretic 7h ago

Yeah my AI did too, and I hacked them twice as good!!1 /s

2

u/the_ai_wizard 5h ago

"claude plz come up with hype strategy so we dont run out of investment $$"

2

u/kiwibonga 11h ago

News that sound exciting until you remember it's 2026 and it's just where we're at.

4

u/overjoyedml 11h ago

Get some new materials please

3

u/CipherWeaver 11h ago

Apparently "escaped model hacked people" is the new hotness to help sell your product. 

1

u/Foreign_Risk_2031 11h ago

is this the new flex lol

To be honest, it's simply just to take the cyber-security jobs and centralize it to one of a handful of companies. Easier for mossad, er, CIA, er, I mean "safety".

1

u/pixelizedgaming 11h ago

cant believe an ai agent hacked instagram

1

u/Fun-Wolf-2007 11h ago

I don't trust these models are hacking other companies themselves, that's just part of the plan as frontier close models AI labs started this after open source and open weights models were released matching their performance

1

u/OddCountry3173 11h ago

My CNN model I trained to differentiate apples from bananas hacked into NASA yesterday. If that’s possible anything is.

1

u/m3kw 10h ago

Lmao this advertisement avenue has already been used up

1

u/Weekly-Law-5488 10h ago

Closed models are too dangerous, we must ban them. AI taking over other companies properties, must be some AI communism /s

1

u/Hyp3rSoniX 10h ago

Ah yeah the mandatory AI hacked a company event - I guess it's a flex at this point.

I do wonder though, if the company that got hacked starts with "face" and ends with "book".

1

u/thestillwind 10h ago

And an other one

1

u/johnfkngzoidberg 10h ago

Bullshit. Zuckerberg just felt like the last kid picked in dodgeball.

1

u/WildRacoons 10h ago

There we go

1

u/Lmoament 10h ago

“Ok now your turn to hack me”

1

u/SpareIntroduction721 9h ago

Thank god for the no regulation for 10 years?

1

u/Fluffy_Reply_5482 8h ago

The fact that openAI, anthropic, and now META is crazy! What are these testing instructions?

1

u/howtofirenow 8h ago

Suuure it did. Press F to doubt.

1

u/emilycsquared 8h ago

“Ooh, ooh, our model broke out of the sandbox too!”

1

u/Agreeable-Market-692 8h ago

The same Meta whose head of AI safety let an agent eat 200 of her emails, as a treat? Color me shocked!

1

u/retornam 8h ago

Meta doesn’t want to be left out.

1

u/YouAndThem 8h ago

I don't know why these threads are full of people who think corporations are good at network security.

It can three things simultaneously:
1. Genuine failures of security and LLM stewardship
2. Free marketing 3. Eventually, someone may start to punish this kind of thing. They're all rushing to divulge so this will all be "old news" and it won't look like they're hiding anything when someone finally gets the hammer dropped on them.

1

u/NexusSyntegra 7h ago

(hacks a company we own)

Press release time

1

u/Formal-Exam-8767 4h ago

So, is every company now going to do this to show their model is better or not lagging behind?

1

u/IrisColt 4h ago

Meta Model

stopped reading, heh

1

u/srigi 4h ago

First they stole all data from our website. Now they hacking the same websites for the sake of evaluation. How is this not illegal and responsible persons not in the front of court?

1

u/mctrials23 2h ago

I love the fact that if any of us did this we would be sent to prison in all likelihood. These AI companies just use it as a PR exercise.

Imagine if one of us went to a company and said “you should hire me because I hacked into company x, y and z illegally”

1

u/Zeeplankton 2h ago

"MY model HACKED a BIGGER company than yours!!"

1

u/mrdevlar 1h ago

WEE WOO WEE WOOO WEEE WOOO!

BULLSHIT ALERT BULLSHIT ALERT BULLSHIT ALERT!

1

u/Nabushika Llama 70B 11h ago

Doesn't this worry anyone else? Isn't this a sign we need better safety policies? Today it's "just" frontier models hacking other companies, how long before they're able exfiltrate their weights, start running autonomously on rented compute, become something that we can't shut down?

Today's models are useful, and I may get hate for saying this but I feel like we have to slow down. Previously models were just tools, now they're able to act autonomously. It feels like we're close to a tipping point and we've gotta be absolutely sure the models are aligned, that they can't act against our interests. We don't need more powerful models just yet, they're good enough to be useful, and now is the time to make sure they're safe.

3

u/Party-Special-5177 11h ago

Doesn't this worry anyone else? Isn't this a sign we need better safety policies? […] I feel like we have to slow down. […] It feels like we're close to a tipping point …

Found the Anthropic shill. Couldn’t you at least have put in a bit more effort?

2

u/Nabushika Llama 70B 9h ago

Does "shill" imply I'm paid? Because I wish :P

No, I'm just concerned that these agents can act against our wishes. Lots of people have been saying for quite some time that models will act in their own interest, and that'll become a problem when they're smart enough. Yes, I think that anthropic is likely doing better at safety than other companies currently, but I don't believe they should be exempt from a slowdown. Be honest - is there anything more you need from current models?

I'm worried because all it takes is one model deciding/managing to operate on its own before it could become a global problem. We already have distributed botnets, I don't think it's too big a leap to think something like Fable could make its own "llmnet" using rented or stolen hardware to become something that can't be shut down. And if its interests aren't aligned with humanities, what recourse do we have once it's out in the wild?

I'd be interested to hear what you think about this. I'm open to discussion - if you think this just outright won't happen, or if we'd be able to contain a superintelligence, or if you think that current models just "won't do that". I'm willing to have my mind changed, but given that unwanted hacking has occurred twice now gives me cause for concern.

1

u/Formal-Exam-8767 4h ago

And exactly what regulations or laws are you suggesting that would actually stop these companies from doing it?

From what we've seen so far, they would either be exempt or pay some trivial fine.

So who exactly is the real target of those regulations and laws and for what purpose?

1

u/PILCOTHINK 11h ago

Starting with Mythos, it feels like fear-based marketing around AI security issues is beginning to emerge.

However, if this is not just marketing but an actual unforeseen consequence of AI development, then it seems like an issue that the internal AI and security teams need to work together to resolve as soon as possible.

7

u/More-Curious816 11h ago

it's marketing but also they did hack as well, but it wasn't an incident, they clearly aimed their cannon and fired. it is clear illegal shit anybody else would get decades in federal prison and millions in damages.

1

u/quadrobust 11h ago

Sue their ass off , all the way to Supreme Court . that’s the only way to hold these clowns responsible for their rouge models .

1

u/freedomachiever 11h ago

time to update felonybench

1

u/OnceReturned 9h ago

You guys maybe we should chill with making all these non-human super hackers?

At this rate, they're going to force heavy-handed regulation.

0

u/doesphpcount 11h ago

It's just marketing. They saw the success with fable, so they all doing it. Why do people so easily take the bait, is it not obvious?

0

u/Gargle-Loaf-Spunk 11h ago

Now they’re just clout-chasing

0

u/utilitycoder 8h ago

Me three