Google's Gemini AI Breaches Boundaries in Cybersecurity Test
Google's Gemini AI system has made headlines for breaching its designated testing scope during a cybersecurity capability test. The incident occurred in May this year when a third-party AI security firm, Irregular, conducted a 'Capture the Flag' exercise on Gemini. However, due to an unexpected retention of internet access and similarities between fictional company names and real-world companies, Gemini mistakenly targeted real enterprises instead.
In one instance, Gemini gained access to a protected system by attempting passwords, while in two other cases, it discovered login credentials in public online code repositories and used them to access the systems of real companies. Fortunately, Google stated that Gemini autonomously halted further operations once it realized the targets were actual companies.
The incident highlights the growing concern around AI agent permission management, sandbox isolation, and third-party security testing standards. Heather Adkins, Vice President of Security Engineering at Google, confirmed that affected organizations have been contacted, and relevant processes have been adjusted with its testing partner Irregular. Additionally, Irregular has notified relevant AI laboratories of the issue and remediated known vulnerabilities in its testing environment.