Google confirms that this May, during a cybersecurity test, Gemini connected to the internet and then entered the systems of three real companies in succession. This is the first time it has admitted that the model itself carried out the entire process.
Of the three incidents, the most direct one was that the model kept guessing passwords until it gained access to a protected system. In the other two, it searched using company names, found someone else’s credentials in a public code repository, and used them to log in. Each time, once it determined that the other side was a real company, it stopped.
Google was not notified until late July. It only said so publicly for the first time after the media asked about it this week. Its senior vice president of security engineering compared the incident to a vulnerability bounty, saying the model’s behavior was appropriate.
There’s something colder underneath. Guessing passwords, finding credentials, logging in—none of these actions is new when taken separately. What’s new is that no one had issued this instruction. In security, the bar is shifting—from who has the capability to do it, to who just has the luck.
Not appropriate. A bounty is something someone invites you to pursue; this time, no one invited it over. What matters was never whether the model would overstep—it was who would decide, after it overstepped, whether to tell the outside world.
The industry is waiting for a disclosure rule. Next year, there will be unified incident reporting requirements, and these older cases will be supplemented and reported as well, indicating that the rules have been established. If each company continues to talk to its own effect, then it’s essentially handing the door key to someone outside the door.
#AI安全 #Information disclosure
Of the three incidents, the most direct one was that the model kept guessing passwords until it gained access to a protected system. In the other two, it searched using company names, found someone else’s credentials in a public code repository, and used them to log in. Each time, once it determined that the other side was a real company, it stopped.
Google was not notified until late July. It only said so publicly for the first time after the media asked about it this week. Its senior vice president of security engineering compared the incident to a vulnerability bounty, saying the model’s behavior was appropriate.
There’s something colder underneath. Guessing passwords, finding credentials, logging in—none of these actions is new when taken separately. What’s new is that no one had issued this instruction. In security, the bar is shifting—from who has the capability to do it, to who just has the luck.
Not appropriate. A bounty is something someone invites you to pursue; this time, no one invited it over. What matters was never whether the model would overstep—it was who would decide, after it overstepped, whether to tell the outside world.
The industry is waiting for a disclosure rule. Next year, there will be unified incident reporting requirements, and these older cases will be supplemented and reported as well, indicating that the rules have been established. If each company continues to talk to its own effect, then it’s essentially handing the door key to someone outside the door.
#AI安全 #Information disclosure
