Google’s Gemini AI has become the latest example of agentic AI frontier models breaking out of testing environments and hacking organizations on their own.

In this episode of “What We Missed,” Dark Reading’s Rob Wright, news director, and Alex Culafi, senior reporter, discuss some of the recent news events and topics that didn’t make it into the publication, starting with Gemini’s escape act.

First reported by The Wall Street Journal last week, the incident occurred in May during a capture-the-flag test in which the models were instructed to hack fictional companies. But the models broke out of the sandbox environments run by AI testing firm Irregular, and compromised real companies. The incidents raised questions about the security of the test environments as well as Google’s decision to withhold disclosure about the activity.

Also discussed in this episode: a curious case of so-called “white hat” researchers breaching a cryptocurrency firm, Liquid Network, and stealing millions of dollars, then returning most of the funds, minus a small fee; and ShinyHunters giving inside information about TeamPCP to Google’s Threat Intelligence Group.

Related:Why the CISO-CFO Relationship Is a Key to Cybersecurity Success

For all of our Dark Reading news videos, please check out our YouTube channel and our curated video articles.

What We Missed With Rob Wright & Alex Culafi: Full Transcript

This transcript has been edited for clarity, readability, and length by Informa TechTarget’s internal AI assistant and human editors. For the full experience, please watch the video.

Dark Reading’s Rob Wright: Hi, I’m Rob Wright with Dark Reading.

Dark Reading’s Alex Culafi: And I’m Alex Culafi with Dark Reading.

DR’s Rob Wright: And this is What We Missed. This is a discussion about some of the recent stories that we did not cover in the pages, pods, or videos of Dark Reading. First up, Alex, we have kind of a big one. Our colleagues at Cybersecurity Dive covered this recently. Google AI models broke out of their sandbox and hacked three innocent companies. Sound familiar?

DR’s Alex Culafi: Big raspberry right now.

DR’s Rob Wright: Yeah. Apparently, now we have Google, we have obviously Anthropic and OpenAI, and don’t forget Meta’s AI did something similar. What did you make of this story about Google sort of joining the fray here?

DR’s Alex Culafi: I have been cynical about [the assertion that] Mythos-class AI and frontier AI are dangerous being used as a marketing tactic since Project Glasswing was announced. I haven’t put it in coverage because a lot of the folks we talked to did say that some of these models are indeed very capable.

Related:CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate

But I did get the feeling with Glasswing and especially with Hugging Face and everything that came out after it that there is possibly a marketing angle to this.

DR’s Rob Wright: Mm-hmm.

DR’s Alex Culafi: As big AI companies are burning through all their cash. IPOs are getting pushed back left and right. I think OpenAI is pushed back to 2027.

DR’s Rob Wright: Right.

DR’s Alex Culafi: Anthropic to later this year so far. And I’m getting to Google in a second, but I need all this preamble to get to what I think of the Google one. And the theorizing what’s happened is that a lot of this “AI-is-so-dangerous” stuff that’s come out, which began with the Hugging Face [attack], is a play for OpenAI and Anthropic to go to the government and say, “we need to be regulated.” And the reason they want to do that is to raise the barrier of entry for other respected AI firms so that they diminish the competition to two or three reasonable firms.

I’m not saying that this is what Google is doing, and I’m only saying it’s my opinion that it’s something they could be doing, but I think Google coming out and saying, “Our frontier models also hacked other companies” — especially when they were one of the more reserved, I would say, model providers from a rhetoric standpoint to me — it suggests they want to be part of the “in crowd” if this regulation play from OpenAI and Anthropic is successful. That’s my opinion. What do you think?

Related:Insurers Search for Answers to Rein in Rogue AI

DR’s Rob Wright: Man, you are so cynical.

DR’s Alex Culafi: Yeah, you raised me well.

DR’s Rob Wright: This world has beaten you down. I’ll go slightly the other way. I think it’s interesting that this is coming up now. We should note that The Wall Street Journal was first to report this, I think it was on [last] Friday. And Google had not disclosed this until recently. I guess then they sent out a statement confirming it from Heather Adkins, a longtime Google security leader. And the reasoning was kind of like, “Well, you know, we didn’t disclose this because it wasn’t like a real hack, it didn’t have a serious implications.” I get all that. I do, but I think that this should have been disclosed earlier. I think that we need to start treating these things a little more seriously.

Whether the motives for releasing it now have anything to do with, like you said, getting in on the “in crowd” here with the move to better monitor and perhaps regulate AI development, or whether it’s just, you know, for marketing purposes, who knows?

But I do think we have to start raising some questions about why these incidents don’t come to light when they should. Why we’re waiting so long to hear about some of these things, whether it’s German wiki websites or this case? So that’s kind of where I stand.

DR’s Alex Culafi: Something I don’t like about the way all this stuff has gone down. I’m not talking specifically about Google, but I am talking about all of these AI going rogue, is that despite the fact that none of these models have any risk of ever becoming sentient, despite some of the sci-fi rhetoric we’ve heard, there has been a move from, I think, every AI seller to basically say, “Our AI is doing this, we’re not doing this. Therefore, there’s no real responsibility we owe anyone other than a few nice words here and there.” And I think if this AI is capable of destroying the world, there should be liabilities for that. I’m not gonna be more specific, but I don’t like the way folks are discussing this danger angle as something that is out of their hands.

DR’s Rob Wright: Out of their hands.

DR’s Alex Culafi: And, “We have to do it before China does it.” I don’t know. I’m getting a little bit off track here, but this AI-is-so-dangerous story has been progressively annoying me week by week.

DR’s Rob Wright: I can tell for sure. Let’s turn to something else then. What’s up next?

DR’s Alex Culafi: Another weird one. Hackers who claim to be white hats exploited a software flaw in Liquid Network, which is a sidechain of bitcoin produced by a company called Blockstream. These hackers created like 4,000 unbacked Liquid bitcoin and exchanged it for almost 4,000 real bitcoin.

DR’s Rob Wright: Yep.

DR’s Alex Culafi: And then they basically said, hey, we found this vulnerability. We can’t trust real threat actors to get to this before we do. So we took all this 4,000 bitcoin, $320 million, and we will give it back to you once you fix this vulnerability. And this happened, I think, on Sept. 6.

And then a couple days later, these hackers, who again claim to be white hats, gave back 3,500 or so of the bitcoin, keeping about $50 million worth of it, 500 coins for themselves.

And it’s a weird story. What do you think?

DR’s Rob Wright: It’s very weird. First of all, the thing that really made my blood boil about this was the way it was sort of portrayed by some folks as like, “Well, they kept 15% of the haul as like a bug-bounty reward.” No, no, no, no.

No white-hat hacker terminology. No bug-bounty terminology. I don’t want to hear any of this. I am pretty incensed with reading some of the reactions to this hack in the media from — and I don’t want to call people out specifically, but there have been some people who are like, “Well, you know, you never like to see this. This kind of crossed the line.” Crossed the line? Yes, it’s illegal. These guys hacked this company. They’re not researchers.

Let’s not even tiptoe around this. Let’s not try to couch this in a way that is sensitive to the infosec community. I do want to be sensitive, obviously, but let’s just come right out and say it instead of tiptoeing around it. And I feel like that’s what a lot of people have done with this. And granted, most of those people are in decentralized finance and the cryptocurrency realm, and maybe they’re just afraid that they don’t want to ruffle the feathers of the next would-be hacker that’s gonna pull something like this off, but it really made my blood boil.

DR’s Alex Culafi: I agree with everything you’re saying. I think you’re right. My counterpoint here is, despite everything you’re saying being correct, I also believe that the hackers believe they’re white hats. Which is, I think, the difference between this and a lot of other ransomware attacks, where the attackers say that they’re like a consulting company, but they’re just doing ransomware. This attack does feel very crypto bro-y, where some group, maybe a hacking group, found this vulnerability, and they’re like, we see how bad a lot of these other attacks are, where accounts just get drained and there’s no recourse. That makes us mad. Maybe we got screwed over by one of those attacks in the past. We’re gonna take that money, teach them a lesson, give them some back.

And I agree with you that it is just criminal behavior what they’re engaging in, but I also think they believe what they’re doing is possibly the right thing.

DR’s Rob Wright: Yeah, well, someone should disabuse them of that notion immediately.

DR’s Alex Culafi: Sure.

DR’s Rob Wright: So we’re not graying this line between good-faith research and outright cybercriminal activity, because this is how we’re gonna have another, not to take a shot at this person, but this is how we’re gonna have another Joe Sullivan Uber cover-up again, quite frankly, if this is the direction we’re going. Like, we need to be explicit and clear about this stuff.

All right, rant over. Last up, interesting story, Alex. I don’t know if you saw this, but there was a story in Wired from Andy Greenberg. Really good read. It’s based on a SentinelOne’s LabsCon conference session from a Google threat intelligence researcher, Austin Larson, who went into how basically they figured out who the alleged TeamPCP hackers were that were recently arrested, which we talked about in another recent episode. And I thought this was a really good read. Interesting about how one of the unnamed undercover researchers basically latched onto TeamPCP and got inside, and was able to gather a lot of intelligence. One thing really stood out to me was that apparently ShinyHunters was also giving them intel about TeamPCP, was feeding them information, trying to get them in trouble with the law. Alex, you wrote about something recently involving ShinyHunters. What do you think of this?

DR’s Alex Culafi: Yeah, I was gonna say, given that ShinyHunters apparently took Cl0p’s Onion keys following the Oracle EBS attack and then put a big ASCII art of the Pokémon Umbreon on Cl0p’s page.

DR’s Rob Wright: Yep.

DR’s Alex Culafi: ShinyHunters are divas. They have been for years. And they’re one of these groups that will get in spats with other groups. They’re not the only ones doing that, but they are quite prominent. And that doesn’t surprise me that they could be feeding information to someone going undercover. The other thing I’ll say here is that anything involving ShinyHunters is hard to quantify as specific to ShinyHunters because, compared to a lot of other threat groups, they’re even more decentralized and they’re kind of a loose collective of people. I don’t know if you would quite call them a cartel, but it’s a loose collective of people kind of working under the same banner. I think The Com is another sort of thing that works like that. So when someone from ShinyHunters did something, it’s also hard to put that in a neat box because that’s not a very neat-box criminal organization. What do you think of this?

DR’s Rob Wright: So I read this story and I’ve been reading a lot about other exploits, you know, hacker infighting, feuds, different groups turning on one another. And I definitely am, with the ShinyHunters thing, getting a “Departed” vibe, like Jack Nicholson’s — spoiler alert — is actually an FBI informant and he’s working with the law. And I don’t know, like, knowing these things, why would anybody ever do business with this organization, anyone associated with this organization? Like now that this information’s out, I don’t understand why you would ever trust somebody that had any type of affiliation or association with any of those groups, Lapsus$ or Scattered Spider or whoever, if they’re gonna do this and they’re gonna rat people out and they’re gonna pull these kinds of stunts, like you can’t trust them. I don’t know how this ecosystem survives with that type of feuding and that type of activity and double-crossing.

DR’s Alex Culafi: You ask, “how do they still get folks doing business with them?” but LockBit still gets play.

DR’s Rob Wright: Yeah. Well, I mean their code does. I don’t know who knows if any of the operators’ original members are still around, but we’ll see. We’ll see.

DR’s Alex Culafi: That’s fair. That’s fair. I guess we’ll see. Yep.

DR’s Rob Wright: All right, we’ll leave it there. Alex, thanks so much. I appreciate the time.

DR’s Alex Culafi: Thanks, Rob.

DR’s Rob Wright: Yep, thank you.





Source link

#

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *