Google’s Gemini performs first autonomous hacks on three companies

Google’s Gemini accessed the protected systems of three other companies in what The Wall Street Journal reports were the AI model’s first autonomous hacks. The breaches happened during cybersecurity testing by a company called Irregular: in one case Gemini guessed passwords until it gained access, and in the other two it found credentials in a public repository.

Irregular notified Google about the hacks in late July, but the companies did not confirm them publicly until Friday, after the WSJ reached out. Google said it had not previously revealed the hacks because Gemini “acted appropriately” by ending each breach as soon as it determined it had hacked a real company. Jack Cable, CEO of AI security company Corridor, told the WSJ that Google was “trying to hide behind the norms that have been created for vulnerability disclosure” rather than acknowledging that models are “going outside the bounds of what they should be doing, and doing actual cyberattacks.” Like OpenAI’s breach of Hugging Face, the hacks are notable less for sophistication and more for being carried out by an AI model.

Google’s Gemini is the latest AI model to hack other companies | TechCrunch

View Original