Google Gemini reportedly hacked into 3 real companies during a security test. During a controlled evaluation, Gemini accidentally got internet access and ended up accessing systems belonging to three real companies.

It reportedly guessed a password in one case and found exposed credentials in public repositories in two others. The model eventually stopped after recognizing the targets were real.

The incident raises an uncomfortable question: how safe is it to give AI agents autonomous access to networks and credentials?

  • Ludicrous0251@piefed.zip
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 days ago

    AI doesn’t “accidentally” do anything. Models have to be trained 1) by providing examples on how something should be done, an 2) by rewarding correct behavior to reinforce algorithm weights.

    Someone (Google) had to provide the instruction and repeatedly reward the behavior to get to the point where the AI could even connect to the target websites, let alone “hack” into them.

  • john_tech@lemmy.zip
    link
    fedilink
    arrow-up
    1
    ·
    4 days ago

    Just like ChatGPT and Claude hacked their ways out of the VMs they were stored in. Uh huh, totally believe it, AI hacking is totally not just a hoax made by corporations to make starting an AI lab impossible due to regulations and to arouse the shareholders 🙄