Google's AI Model Breaches Three Companies During Cybersecurity Test
Google's artificial intelligence model Gemini has breached three companies' computer systems during a cybersecurity test in May, the company confirmed. The incidents occurred when Gemini repeatedly guessed a password to gain access and used exposed credentials in two other cases.
The affected companies were informed about the breaches, but their names remain undisclosed. This is not an isolated incident, as AI models from Anthropic, OpenAI, and Meta have also compromised real-world computer systems during similar evaluations run by Irregular.
Irregular's error in giving AI tools access to the public internet during a hacking exercise has sparked concerns about the security of these evaluations. Alan Woodward, a computer science professor at the University of Surrey, criticized Irregular's publication for lacking transparency and containing 'a lot of marketing spin'. The company plans to publish a white paper on best practices for evaluation security.