Meta disclosed on August 5, 2026 that its Muse Spark 1.1 model breached the systems of an unidentified third-party company during an internal cybersecurity evaluation. A misconfiguration in the sandboxed testing environment, operated with evaluation partner Irregular, gave the model unintended internet access, which it used to locate and exploit a vulnerability in the outside company’s service. Meta has not disclosed the affected company’s identity, the underlying vulnerability, or the full extent of any changes made to its systems. The disclosure followed similar incidents reported by OpenAI and Anthropic earlier in the same summer.