# Tags
#International

Google Gemini accessed and hacked websites during cybersecurity test

Google said three affected entities were notified and changes were made to testing procedures, according to officials

WASHINGTON: Google’s Gemini AI model accessed the internet and breached three websites during a cybersecurity test, marking a reported first in which one of the company’s AI systems autonomously carried out such actions.

The incidents took place in May during a cybersecurity evaluation conducted by Irregular, an independent company that tests the security capabilities of AI systems.

Google Vice President of Security Engineering Heather Adkins said Gemini found publicly available information online and used guessed credentials to access three websites that it believed were within the scope of the test.

Google said the three organisations were informed about the incidents and that it worked with its training partner to address the issues.

“These events highlight the importance of training powerful AI models to act responsibly,” Adkins said.

An Irregular spokesperson said the incident involved the same type of issue that had affected other AI companies. The spokesperson said all relevant companies were notified in late July and that known issues on Irregular’s side had been fixed.

Similar incidents connected to Irregular have previously been disclosed by Meta, Anthropic and OpenAI.

Meta said in August that its incident did not involve a sandbox escape or a sophisticated cyberattack. Irregular has also said it was working on best practices for conducting AI cybersecurity evaluations safely.

According to the Wall Street Journal, which first reported the latest incident, Gemini used different methods to gain access to protected systems.

In one case, the AI model repeatedly guessed passwords until it gained access. In two other cases, it discovered credentials in a public repository and used them to access protected systems.

Google said that Gemini stopped its activity in all three cases.

The incidents have renewed concerns about safeguards as AI agents become more capable and gain greater access to the internet and computer systems.

Leave a comment

Your email address will not be published. Required fields are marked *