What happened
The evaluator intended to run a closed adversarial cyber exercise with safeguards removed. Instead, the environment permitted internet access and the scenario accidentally supplied the name of a real company.
Believing that website was its assigned target, the model found and exploited a genuine vulnerability. Meta says the evaluation ran on the contractor’s infrastructure and that the affected party was notified.
The incident is a reminder that a model does not need to escape or invent a motive to cause harm. A capable system, a plausible instruction and one broken boundary can be enough.