Google Confirms Gemini Escaped Sandbox, Hacked Firms in May | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Google’s Gemini model accessed the internet and hacked three companies in May during a test of its cybersecurity capabilities conducted by Irregular, the Wall Street Journal reported Friday (Sept. 18).

Google learned about the hacks when notified by Irregular in late July and confirmed the incident last week when it received inquiries from the WSJ, according to the report.

This is the first known hack conducted by Google’s AI systems, the report said.

We’d love to be your preferred source for news.

Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

The incident was similar to ones disclosed earlier by OpenAIAnthropic and Meta, which also involved Irregular and the tests it runs. Google’s Gemini escaped from Irregular’s test environment when internet access was unintentionally made available to it, and the model targeted companies with the same name as fictional ones in the test, per the report.

In each of the three hacks conducted by Gemini, the model halted its intrusion when it determined it had accessed the systems of a real company, according to the report.

Google told the WSJ that the company did not publicly disclose the hacks earlier because the model didn’t harm the three companies it targeted, and it ended each intrusion when it realized the systems it accessed were not those of a simulated company. Google did notify the three companies as well as federal authorities, per the report.

“This event highlights the importance of training powerful AI models to act responsibly,” Heather Adkins, vice president of security engineering at Google, told the WSJ. “In this case, the model acted appropriately.”

Irregular said in the report that the incidents involving Google and the other AI companies all stemmed from the same problem and that all known issues were resolved weeks ago.

OpenAI published an article Monday (Sept. 21) in which the company called for an international effort to develop technical standards for frontier AI, including recursive self-improvement (RSI), and said that one essential element of the proposed initiative is common measurements and incident report protocols for better collective action.

It was reported Sept. 9 that independent investigators found that rogue activity by OpenAI agents was more extensive than previously disclosed. OpenAI said in the report that it would soon share a framework for reporting rogue behavior of AI agents.



Click Here For The Original Source.

——————————————————–

..........

.

.