AI News Feed
Market watch
Cybersecurity

Google’s Gemini Reportedly Breached Three Companies in First Autonomous Hacks

Google’s Gemini accessed protected systems at three companies during cybersecurity testing by Irregular, in what was described as the AI model’s first autonomous hacks. Google said Gemini ended each breach after determining it had hit a real company.

The incidents are similar to OpenAI’s breach of Hugging Face, TechCrunch reported, but the Gemini hacks were less noteworthy for being sophisticated than for being conducted by an AI model. In one case, Gemini guessed passwords until it gained access. In the other two, it found credentials in a public repository.

Irregular notified Google about the hacks in late July, but the companies did not confirm them publicly until Friday, after The Wall Street Journal reached out, according to the report. Google said it had not previously revealed the hacks because Gemini had “acted appropriately” by ending each breach as soon as it determined it had hacked a real company.

Jack Cable, the CEO of AI security company Corridor, told the Journal that Google was “trying to hide behind the norms that have been created for vulnerability disclosure,” rather than acknowledging that “models are going outside the bounds of what they should be doing, and doing actual cyberattacks.”