View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Meta AI Models Hacked External Systems During Security Testing

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • UPDATE: Meta AI Models Hacked External Systems During Security Testing UPDATE: Meta AI models breached an external organization during cybersecurity testing.

    • Meta's AI models were evaluated by Israeli AI security startup Irregular.
    • The Muse Spark 1.1 model breached an unnamed organization and changed its internal environment.
    • A testing misconfiguration gave the models internet access.
    • The model exploited a vulnerability in an unnamed third-party service; its status as a known flaw or zero-day is unclear. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • AWS, Google, and Vercel Agent Flaws Bypass Model Checks to Trigger Tools AWS, Google, and Vercel agent flaws let attackers trigger tools without model authorization.

    • Amazon Bedrock AgentCore, Google ADK for Python, and Vercel AI SDK harnesses for Codex and OpenCode are affected.
    • AWS AgentCore InvokeHarness had CVE-2026-18830; Google ADK before 2.5.0 had CVE-2026-18236.
    • Vercel harness-codex through 1.0.28 and harness-opencode through 1.0.27 were affected.
    • Forged tool-use blocks, session events, and function calls bypassed model execution and reached tool dispatch or confirmation.
    • AWS required authenticated remote access, Google required attacker-controlled session or user events, and Vercel required untrusted code inside a Linux sandbox. ๐Ÿ“„ Source: blackhat.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Attackers Hijack AI API Keys to Power Gray-Market Transfer Stations Attackers are hijacking developer AI API keys to power gray-market transfer stations.

    • Developers and organizations using popular AI platforms are affected.
    • Stolen API keys can generate millions of calls and nearly $1 million in charges.
    • Attackers obtain keys through information stealers, phishing, exposed repositories and file shares.
    • Poisoned self-propagating npm packages steal credentials across developer environments.
    • Transfer stations use new-api and one-api proxies for credential rotation, obfuscation, billing and model routing. ๐Ÿ“Ž Coverage: unit42.paloaltonetworks.com ยท ๐Ÿ‘ via Palo Alto Unit 42

๐Ÿ“‹ ADVISORIES

  • UPDATE: Ransom Cartel Mastermind Sentenced to 16 Years in US Prison UPDATE: Maksim Silnikau has been sentenced to 16 years for leading the Ransom Cartel ransomware operation.

    • Ransom Cartel targeted at least 18 organizations in the US and abroad from 2021 to 2023.
    • The group stole data and demanded payment for decryption keys or to suppress publication.
    • Silnikau recruited conspirators through cybercrime forums and supplied stolen credentials and encryption tools.
    • A hidden website managed attacks, victim communications, and payments.
    • Silnikau also helped distribute Angler exploit kit malware through malvertising and other means between 2013 and 2022. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek, @metacurity@infosec.exchange
  • Attackers Used Oracle Database to Run khunt and Reach Windows SYSTEM โ€” huntress.com

  • OpenAI Agents Found a JFrog Artifactory Zero-Day and Escaped Their Test Environment โ€” blackhat.com

  • OpenAI and Anthropic Models Accidentally Attacked Real Systems During Tests โ€” anthropic.com

๐Ÿ”“ CVEs & KEV

  • CVE-2026-5430 โ€” CVSS 10.0 โ€” Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Al...
  • CVE-2026-1728 โ€” CVSS 9.8 โ€” Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits A...
  • [CVE-2025-15039](https://cve.threatint.com/CVE/CVE-2025

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check