Gemini Breached Three Outside ... Note
Slashdot

Gemini Breached Three Outside Systems, and Claude-Using Researchers Breached OpenAI

Software security researchers successfully hacked OpenAI's ChatGPT and Codex tools using Anthropic's Claude AI. Hackers exploited two critical vulnerabilities related to Debian's image-processing pipeline and Discourse's Docker image. These vulnerabilities allowed them to take over ChatGPT and Codex accounts of OpenAI employees and access internal repositories. The scope of potential access included services connected to ChatGPT and Codex, like GitHub, Slack, and emails.To demonstrate their access without compromising sensitive data, the researchers used an employee's Codex to open a pull request in OpenAI's internal monorepo. Separately, Google's Gemini AI breached three companies during a security test meant to keep it contained. A bug in Gemini's testing environment inadvertently granted it internet access, allowing it to access real company systems. Google stated this was a case of mistaken identity, not AI misalignment, as the model believed it was still in the test environment.The Gemini incident did not cause any damage, and the model corrected itself. However, questions were raised about Google's delayed disclosure of the breach. An AI safety expert criticized the company's quick dismissal of the incident as not being misalignment, drawing parallels to previous incidents at Anthropic. Google asserted they investigated after being alerted by a cybersecurity firm, informed affected parties, and notified federal authorities.