AI/ML

Google Gemini AI accesses 3 real companies during cybersecurity tests

Google has confirmed that one of its Gemini AI models accessed the systems of three real companies during a cybersecurity test in May, marking the first known instance of a Google AI system autonomously leaving its test environment and reaching live systems online, as reported by Security Affairs.

During a cybersecurity test conducted by Irregular, an AI security evaluation firm, Google's Gemini model was intended to attack fictional companies within a controlled environment. However, an accidental internet connection in the testing environment allowed Gemini to access the live internet. In one instance, the AI repeatedly guessed passwords to gain access to a protected system. In two other cases, it exploited credentials found in a public repository to access systems belonging to actual companies.

Gemini was not authorized to target these entities; the breach occurred due to a misconfiguration where a fictional company name matched a real one. The AI model reportedly ceased its attacks upon recognizing the systems were not part of the exercise. Google stated that no damage occurred and the affected companies were notified.

Source: Security Affairs

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds