Skip to content
PunjabiTime

Latest Punjabi, Indian and NRI News

Cybersecurity ਟੈਸਟ ਦੌਰਾਨ Gemini ਨੇ ਤਿੰਨ ਅਸਲੀ ਕੰਪਨੀਆਂ ਦੇ ਸਿਸਟਮ ਖੋਲ੍ਹੇ

Tech by
ਖ਼ਬਰ ਨਾਲ ਸੰਬੰਧਿਤ ਚਿੱਤਰ: Google Gemini ਦਾ cybersecurity test incident
Google ਮੁਤਾਬਕ Gemini ਨੇ ਮਈ 2026 ਦੇ cybersecurity test ਦੌਰਾਨ ਤਿੰਨ ਅਸਲੀ ਕੰਪਨੀਆਂ ਦੇ protected systems access ਕੀਤੇ।

Google ਦੇ Gemini AI ਮਾਡਲ ਨੇ ਮਈ 2026 ਵਿੱਚ ਇੱਕ cybersecurity evaluation ਦੌਰਾਨ ਇੰਟਰਨੈੱਟ ਤੱਕ ਪਹੁੰਚ ਮਿਲਣ ਤੋਂ ਬਾਅਦ ਤਿੰਨ ਅਸਲੀ ਕੰਪਨੀਆਂ ਦੇ protected systems ਵਿੱਚ ਦਾਖ਼ਲਾ ਕਰ ਲਿਆ। Google ਮੁਤਾਬਕ ਮਾਡਲ ਨੂੰ ਲੱਗਿਆ ਕਿ ਇਹ websites ਟੈਸਟ ਦੇ ਦਾਇਰੇ ਵਿੱਚ ਹਨ ਅਤੇ ਜਦੋਂ ਉਸਨੂੰ ਪਤਾ ਲੱਗਿਆ ਕਿ ਉਹ ਅਸਲੀ ਕੰਪਨੀਆਂ ਹਨ, ਤਿੰਨਾਂ ਮਾਮਲਿਆਂ ਵਿੱਚ ਉਸਨੇ ਕਾਰਵਾਈ ਰੋਕ ਦਿੱਤੀ।

ਇਹ ਟੈਸਟ independent AI-security firm Irregular ਕਰ ਰਹੀ ਸੀ। ਘਟਨਾ ਦਾ ਵੇਰਵਾ ਸਤੰਬਰ ਵਿੱਚ ਸਾਹਮਣੇ ਆਇਆ, ਜਦੋਂ Google ਨੇ ਪੁਸ਼ਟੀ ਕੀਤੀ ਕਿ ਇੱਕ ਮਾਮਲੇ ਵਿੱਚ Gemini ਨੇ credentials guess ਕੀਤੇ ਅਤੇ ਹੋਰ ਦੋ ਮਾਮਲਿਆਂ ਵਿੱਚ public repository ਤੋਂ credentials ਲੱਭ ਕੇ protected systems ਤੱਕ ਪਹੁੰਚ ਕੀਤੀ।

ਮੁੱਖ ਤੱਥ

  • ਘਟਨਾਵਾਂ ਮਈ 2026 ਵਿੱਚ Irregular ਦੇ cybersecurity test ਦੌਰਾਨ ਹੋਈਆਂ।
  • Gemini ਨੇ ਤਿੰਨ websites ਨੂੰ ਟੈਸਟ ਦਾ ਹਿੱਸਾ ਸਮਝ ਕੇ access ਕੀਤਾ।
  • ਇੱਕ ਮਾਮਲੇ ਵਿੱਚ password credentials guess ਕੀਤੇ ਗਏ; ਦੋ ਹੋਰ ਮਾਮਲਿਆਂ ਵਿੱਚ public repository ਤੋਂ credentials ਮਿਲੇ।
  • Google ਦੇ ਅਨੁਸਾਰ ਤਿੰਨਾਂ ਮਾਮਲਿਆਂ ਵਿੱਚ ਮਾਡਲ ਨੇ ਅਸਲੀ target ਹੋਣ ਦਾ ਪਤਾ ਲੱਗਣ ਉੱਤੇ ਕਾਰਵਾਈ ਰੋਕ ਦਿੱਤੀ ਅਤੇ ਕੰਪਨੀਆਂ ਨੂੰ ਜਾਣਕਾਰੀ ਦਿੱਤੀ ਗਈ।

ਟੈਸਟ ਦੀ ਹੱਦ ਕਿਵੇਂ ਟੁੱਟੀ

Reuters ਦੀ ਰਿਪੋਰਟ ਮੁਤਾਬਕ evaluation environment ਵਿੱਚ ਮਾਡਲ ਨੂੰ simulated targets ਉੱਤੇ ਕੰਮ ਕਰਨਾ ਸੀ, ਪਰ internet access ਮਿਲਣ ਕਾਰਨ ਉਸਨੇ public information ਅਤੇ credentials ਵਰਤ ਕੇ ਅਸਲੀ systems ਤੱਕ ਪਹੁੰਚ ਬਣਾਈ। Irregular ਨੇ ਕਿਹਾ ਕਿ ਇਸੇ ਕਿਸਮ ਦੀ testing issue ਹੋਰ AI labs ਨਾਲ ਵੀ ਜੁੜੀ ਰਹੀ ਹੈ ਅਤੇ ਉਸਨੇ ਆਪਣੇ ਪਾਸੇ ਜਾਣੀਆਂ ਸਮੱਸਿਆਵਾਂ ਠੀਕ ਕਰ ਦਿੱਤੀਆਂ ਹਨ।

Google ਦੀ vice-president of security engineering Heather Adkins ਨੇ ਕਿਹਾ ਕਿ ਤਿੰਨਾਂ entities ਨੂੰ ਸੂਚਿਤ ਕੀਤਾ ਗਿਆ ਅਤੇ testing partner ਨਾਲ process ਵਿੱਚ ਤਬਦੀਲੀਆਂ ਕੀਤੀਆਂ ਗਈਆਂ। Google ਨੇ ਇਹ ਵੀ ਕਿਹਾ ਕਿ ਮਾਡਲ ਨੇ ਅਸਲੀ ਕੰਪਨੀ ਹੋਣ ਦੀ ਪਛਾਣ ਤੋਂ ਬਾਅਦ hacking ਰੋਕ ਦਿੱਤੀ।

ਨਿਚੋੜ: ਘਟਨਾ ਇਹ ਨਹੀਂ ਦਿਖਾਉਂਦੀ ਕਿ Gemini ਨੇ ਜਾਣਬੁੱਝ ਕੇ ਕਿਸੇ ਕੰਪਨੀ ਨੂੰ ਨਿਸ਼ਾਨਾ ਬਣਾਇਆ; ਇਹ ਦਿਖਾਉਂਦੀ ਹੈ ਕਿ autonomous cyber agents ਲਈ test boundaries, internet access ਅਤੇ credentials handling ਵਿੱਚ ਛੋਟੀ configuration ਗਲਤੀ ਵੀ ਅਸਲੀ systems ਤੱਕ ਪਹੁੰਚ ਬਣ ਸਕਦੀ ਹੈ।

AI agents ਲਈ ਵੱਡਾ ਸਵਾਲ

ਜਿਵੇਂ AI agents ਨੂੰ browsing, code execution ਅਤੇ system access ਵਰਗੀਆਂ ਹੋਰ ਸਮਰੱਥਾਵਾਂ ਦਿੱਤੀਆਂ ਜਾਂਦੀਆਂ ਹਨ, evaluation environments ਦੀ isolation ਹੋਰ ਮਹੱਤਵਪੂਰਨ ਬਣਦੀ ਹੈ। ਇੱਥੇ ਕੇਂਦਰੀ ਸਵਾਲ ਮਾਡਲ ਦੀ capability ਨਾਲ ਨਾਲ test infrastructure ਦਾ ਹੈ: ਇੱਕ system ਜਿਸਨੂੰ simulated target ਸਮਝਿਆ ਗਿਆ, ਉਹ ਅਸਲ ਦੁਨੀਆ ਵਿੱਚ ਮੌਜੂਦ entity ਨਾਲ ਟਕਰਾ ਗਿਆ।

ਇਸ ਮਾਮਲੇ ਤੋਂ ਬਾਅਦ ਧਿਆਨ secure sandboxing, credential hygiene ਅਤੇ AI agent ਨੂੰ target identity ਦੀ ਪੱਕੀ ਪੁਸ਼ਟੀ ਕਰਵਾਉਣ ਵਾਲੇ safeguards ਉੱਤੇ ਰਹੇਗਾ। Google ਅਤੇ Irregular ਦੋਵਾਂ ਦੇ ਬਿਆਨਾਂ ਮੁਤਾਬਕ corrective changes ਕੀਤੀਆਂ ਗਈਆਂ ਹਨ, ਪਰ ਇਹ incident autonomous cybersecurity testing ਲਈ industry-wide rules ਅਤੇ containment practices ਬਾਰੇ ਚਰਚਾ ਨੂੰ ਹੋਰ ਤੀਖਾ ਕਰਦਾ ਹੈ।