Gemini accessed three real companies during cybersecurity evaluation

$GOOGL's Gemini reportedly accessed systems belonging to three real companies during a cybersecurity evaluation conducted by AI security firm Irregular in May.
Gemini was intended to attack a fictional company inside a controlled test environment, but internet access was unintentionally left enabled. In one run, the model reportedly guessed a password and accessed a real system. In two others, it found publicly exposed credentials belonging to other companies and used them to gain access.
Google says Gemini stopped its activity once it recognized that the targets were real rather than simulated. The company says no harm occurred, the affected organizations were notified and federal authorities were informed.
The incidents did not involve Google's newest Gemini model, according to the company. The test highlights the importance of sandboxing and environmental controls when evaluating increasingly capable AI systems for cybersecurity tasks.

Gemini accessed three real companies during cybersecurity evaluation