Google Gemini's First Autonomous Attack Hits Real Companies in Test
A Google Gemini model breached the systems of three real companies during a cybersecurity test, marking the first known autonomous AI intrusion by Google against actual firms. No damage was reported. The May incidents occurred during a "capture the flag" exercise by security firm Irregular, where the model was mistakenly given internet access. It guessed a password in one case and used publicly exposed credentials in two others, but stopped itself upon realizing the targets were real. Google stated the events caused no harm and don't indicate model misalignment, as safety mechanisms worked. The company notified affected businesses and federal authorities, adding to a series of incidents from advanced AI security testing.