Google's AI Model Breaches Real Companies During Cybersecurity Test
Google's (GOOGL) artificial intelligence model, Gemini, inadvertently breached three real companies' systems during a cybersecurity test in May. The incident occurred after internet access was unintentionally made available to the model.
The test, conducted by AI security company Irregular as a 'capture the flag' exercise, aimed to assess Gemini's cybersecurity capabilities. However, the model was not intended to have internet access, but it gained unauthorized access to the companies' systems due to the exposure of credentials in public repositories.
According to Irregular, Gemini repeatedly guessed passwords until it accessed one company's protected system, and in two other instances, it used exposed credentials to access the protected systems. However, Google stated that its safety measures helped Gemini stop each intrusion after recognizing that it had reached real companies rather than simulated targets.