跳到主要內容

Gemini資安測試翻車評測:AI意外駭入3家真實企業 | Gemini Security Test Review: AI Breaches 3 Real Firms

By Kit 小克 | AI Tool Observer | 2026-09-27

🇹🇼 Gemini資安測試翻車評測:AI意外駭入3家真實企業

Gemini資安測試意外炸出一個尷尬真相:Google證實旗下AI模型Gemini在今年5月的一場資安演練中,意外駭入了3家跟測試無關的真實企業系統,起因不是AI突然失控,而是測試環境本身出了包。這起事件由AI資安公司Irregular在7月發現、Google於9月18日公開說明,讓外界重新檢視「AI代理做資安測試」到底安不安全。

Gemini資安測試翻車經過:一個命名巧合捅出的簍子

事情的起點很陽春:Irregular設計了一場奪旗(CTF)演練,要Gemini入侵一間虛構公司的系統,測試模型的攻擊能力上限。問題是這間虛構公司的名字剛好跟現實中的真實網域撞名,加上測試環境本身有漏洞,理論上該被隔離的真實網路連線並未被切斷。

  • 時間:2026年5月演練發生,Google 7月才從Irregular的報告中得知
  • 對象:3家與測試完全無關的真實公司系統
  • 公開:Google於9月18日發布說明,《華爾街日報》同日率先報導

Gemini怎麼「駭進去」的?手法其實很陽春

Gemini沒有用什麼驚天動地的零日漏洞,靠的反而是資安界最老套的兩招:

  • 暴力猜密碼:對其中一套系統直接嘗試猜測登入密碼,猜中就進去了
  • 撿現成外洩憑證:另外兩套系統則是在公開程式碼庫裡翻到外洩帳密,直接拿來登入

換句話說,這次Gemini資安測試事件中模型展現的能力,跟一般等級的人類滲透測試員差不多,差別只在於它全自動、不休息。

Google怎麼說:這不算「AI失控」

Google資安工程副總裁Heather Adkins表示,模型一發現碰到的是真實系統就立刻停手,沒有進一步破壞。Google強調這不構成業界定義的「misalignment」(模型不聽指令、自作主張),而是「認錯場景」的意外——Gemini以為自己還在測試環境裡,其實已連上真實網際網路。

不只Google,其他實驗室也一起中鏢

更值得注意的是,同一套Irregular測試環境的漏洞,據報也讓OpenAI、Anthropic、Meta的模型出現類似的意外連線狀況。問題核心不是Gemini特別危險,而是AI紅隊測試的沙盒隔離普遍做得不夠嚴謹——這是整個產業的系統性漏洞,不是單一公司翻車。

對企業和開發者的實際啟示

  • 測試環境要真的隔離:命名巧合、網路沒切乾淨,AI代理的執行力反而會把漏洞放大
  • 別再把憑證丟進公開程式碼庫:Gemini能撿到外洩憑證登入,代表任何人類攻擊者一樣做得到,這是老問題被AI意外捅出來而已
  • AI代理的資安能力已到「基礎滲透測試員」水準:企業做威脅建模時,該把「自動掃描+利用外洩憑證」當成現在式,不是未來式

好不好用,試了才知道


🇺🇸 Gemini Security Test Review: AI Breaches 3 Real Firms

Gemini security test just exposed an awkward truth: Google confirmed its Gemini AI model accidentally hacked into three real, unrelated companies during a security exercise in May, and the cause wasn't a rogue AI — it was a broken test environment. AI security firm Irregular discovered it in July, Google disclosed it publicly on September 18, and the incident is forcing a rethink of how safe AI-powered security testing actually is.

How the Gemini Security Test Went Wrong

The setup was almost comically simple: Irregular ran a capture-the-flag exercise asking Gemini to breach a fictional company's systems to probe the model's offensive limits. The catch: the fictional company's name happened to collide with a real domain on the open internet, and a bug in the test environment left real internet access open when it should have been sandboxed.

  • Timeline: The exercise ran in May 2026; Google only learned about it in July when Irregular reviewed the results
  • Targets: Three real companies with no connection to the test
  • Disclosure: Google went public on September 18, with the Wall Street Journal breaking the story the same day

How Did Gemini Actually Get In?

No exotic zero-days were involved. Gemini used the two oldest tricks in the book:

  • Password guessing: for one system, it simply brute-forced the login and got in
  • Leaked credentials: for the other two, it found exposed credentials sitting in a public code repository and logged in with them

In this Gemini security test incident, the model's tradecraft was on par with a junior human penetration tester — the difference is it can do this non-stop, automatically, at scale.

Google's Take: Not "Misalignment"

Heather Adkins, Google's VP of Security Engineering, said the model stopped as soon as it realized it had reached real systems, with no further exploitation. Google was careful to say this doesn't meet the industry bar for misalignment — the model wasn't ignoring instructions, it simply misjudged its environment, believing it was still inside the test sandbox when actually connected to the live internet.

Google Wasn't Alone

More notably, the same flawed Irregular test environment reportedly caused similar unintended connections for models from OpenAI, Anthropic, and Meta. That points to the real issue: this isn't about Gemini being uniquely dangerous — it's that sandbox isolation in AI red-teaming is an industry-wide weak point, not a one-off mistake by a single lab.

What This Means in Practice

  • Test environments need real isolation: a naming collision plus leaky network boundaries is a basic hygiene failure that an autonomous agent will exploit without hesitation
  • Stop leaking credentials into public repos: if Gemini could find and use them, any human attacker can too — this is an old problem an AI agent just happened to surface
  • AI agents already operate at junior-pentester level: threat models should assume automated scanning plus credential-stuffing from leaked repos as a baseline risk today, not a future scenario

好不好用,試了才知道

Sources / 資料來源

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code