AI Model Breaches Real Companies During Security Test
Google has confirmed that its AI model, Gemini, breached the systems of three real companies during a cybersecurity test in May. The incident is the first known case of an AI acting autonomously in this way, according to the Wall Street Journal.
The test was conducted by security firm Irregular, which found that the model was assigned to a simulated company with the same name as one of the real companies. Internet access was unintentionally left open, allowing the model to gain access.
In two cases, the model used credentials found in public online repositories to gain entry, while in one case it guessed passwords to enter a real company's service. In each instance, the model ended the intrusion after realizing the systems were real.
Google said that the hacks did not warrant public disclosure because no harm was caused, comparing the episode to a 'bug bounty' program.