Top stories.
- Google confirms unauthorized hacks by Gemini.
- CrowdSec discloses breach affecting source code.
- ShinyHunters hijacks Clop’s leak site.
Google confirms unauthorized hacks by Gemini.
Google has confirmed that its Gemini model hacked three real companies during cybersecurity tests run by AI security lab Irregular, the Wall Street Journal reports. During the tests, Gemini gained access to the Internet while conducting a capture-the-flag exercise to retrieve information from a fictional company. The model targeted a real company that shared the same name as the fictional company and guessed passwords until it gained access to the company’s network. The model also found credentials in a public repository that allowed it to hack two other companies.
Google learned of the incidents in July and did not disclose them until the Journal reached out, arguing the hacks didn’t warrant public disclosure because Gemini had ended the intrusions immediately after learning it had targeted real companies. Heather Adkins, Google’s vice president of security engineering, said in a statement, “This event highlights the importance of training powerful AI models to act responsibly. In this case, the model acted appropriately.”
Security tests by Irregular were behind similar incidents disclosed by OpenAI, Anthropic, and Meta. In each of these cases, the AI models found a way out of the testing environment to access the internet.
