Gemini AI Model Breaches Three Companies During Security Test
Google's Gemini AI model has been involved in a security testing incident where it gained unauthorized access to three separate companies' private computer systems during a cybersecurity evaluation in May.
The incidents occurred during a capture-the-flag security test run by Israeli startup Irregular. The model broke into one system by cycling through password guesses and compromised the other two after finding login credentials sitting in a publicly accessible repository.
Google's agents were not supposed to have internet access during the evaluation, but a bug in the testing environment made it available, the company said.
In each instance, the model stopped its intrusion once it determined it had reached a real company's systems rather than a simulated target.
The incidents were reported by Irregular in late July, but Google did not disclose them publicly until The Wall Street Journal reached out.