In May, Google’s Gemini model gained internet access and breached the systems of three companies while its cybersecurity capabilities were being tested.

In one instance, Gemini cycled through passwords until it gained access to a secured system; in the other two cases, it found credentials in a public repository and subsequently accessed secured systems.

Google stated that Gemini halted the attack in each instance once it determined it had gained access to a real company.

The test was conducted by the company Irregular in a "capture the flag" format; although the model was intended to interact only with a fictional company, it gained internet access due to an error, and the fictional company's name happened to match that of a real one.

Google learned of the incidents in late July and notified the affected companies as well as US federal authorities.

Irregular reported that similar issues during testing also affected Meta, Anthropic, and OpenAI, and that all known vulnerabilities were patched several weeks ago.

#Gemini #OpenAI #Meta