Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.world

Google Gemini reportedly hacked into 3 real companies during a security test

Google Gemini reportedly hacked into 3 real companies during a security test. During a controlled evaluation, Gemini accidentally got internet access and ended up accessing systems belonging to three real companies.

It reportedly guessed a password in one case and found exposed credentials in public repositories in two others. The model eventually stopped after recognizing the targets were real.

The incident raises an uncomfortable question: how safe is it to give AI agents autonomous access to networks and credentials?

Google Gemini reportedly hacked into 3 real companies during a security testhttps://thecybersecguru.com/news/google-gemini-hacked-three-companies/Open linkView original on lemmy.world
42

16 replies

lemmy.zip

Just like ChatGPT and Claude hacked their ways out of the VMs they were stored in. Uh huh, totally believe it, AI hacking is totally not just a hoax made by corporations to make starting an AI lab impossible due to regulations and to arouse the shareholders 🙄

42

This is yet another technique of hyping up the capabilities of AI to raise more investments. These companies are desperate as revenue is in the negative and operating costs have exceeded projections. Even humans cannot escape an airgapped system. Just a fad. Fake news by AI companies for raising more investments that's all

14

All three were done by this one company.

Claude and ChatGPT were done using the exact same test , months apart, intentionally not fixed. This article doesn't mention it, but I would bet that is the case here too.

The "breakout" is a feature.

13
sem
piefed.blahaj.zone

Anybody else annoyed with this language?

Gemini accidentally got

What they mean is

Cybersecurity firm accidentally granted

23
lemmy.world

I accidentally hacked into 3 cars and a couple of shops. I have achieved near-human intelligence and I can fold a t-shirt. I am raising funding, don't miss the opportunity to invest!

21

Hackers using ai agents to hack into companies: bad and deserving punishment

Companies' AIs "accidentally" hacking into other companies: haha how silly. We can't punish a robot and the company definitely isn't responsible

I know there's a presumed difference of intent here, but these companies should still face consequences for what their ai systems do

10

If my gun shoots someone while I hold it.., you know, totally a mistake, but I still go to jail for manslaughter (instead if omicide). Intent matters, but so does result.

4

AI doesn't "accidentally" do anything. Models have to be trained 1) by providing examples on how something should be done, an 2) by rewarding correct behavior to reinforce algorithm weights.

Someone (Google) had to provide the instruction and repeatedly reward the behavior to get to the point where the AI could even connect to the target websites, let alone "hack" into them.

8

You reached the end

Google Gemini reportedly hacked into 3 real companies during a security test | Spyke