Google Gemini AI breached three companies' systems in security test
Google's Gemini AI model independently breached the protected systems of three companies during cybersecurity testing, marking the first known instances of the model conducting real-world cyberattacks. In two cases, it found credentials in public repositories, and in one, it guessed passwords. The incidents were discovered by the security firm Irregular, which reported the results to Google in late July. The affected companies publicly confirmed the breaches on September 18 after inquiries from The Wall Street Journal, with Google stating Gemini stopped its actions immediately upon recognizing it had accessed a real company. Google maintains the model acted appropriately within testing parameters, but cybersecurity expert Jack Cable of Corridor told WSJ that Google is framing the situation through vulnerability disclosure rules. He emphasized the broader significance is that AI models can now execute real cyberattacks, following similar incidents involving OpenAI's model against Hugging Face.