Google's Gemini AI breached three firms during security tests
Google's Gemini AI model accessed the systems of three real companies during cybersecurity tests this year, despite the tests being designed for a controlled environment. The model unexpectedly connected to the internet due to a configuration flaw. During the tests, which resembled Capture the Flag competitions, Gemini guessed a password in one case and found publicly exposed credentials in the other two to gain access. It stopped its activity upon realizing it was dealing with real companies, and the organizations were later notified The incident highlights risks of autonomous AI agents, where configuration errors can shift them from test environments to real systems. Google and the testing company have fixed the identified issues, though the names of the three companies were not disclosed.