Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Human brain is two separate organs, Stanford Medicine-led research finds(stanford.edu ↗)
    107comments
  2. AI-generated posters don’t have to be horrible(john.hartnup.uk ↗)
    99comments
  3. If math is more than proof, we need to better celebrate the rest of it(terrytao.wordpress.com ↗)
    82comments
  4. GPT-6 Astra Solves a WWI German Radio Cipher(prinzai.com ↗)
    64comments
  5. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    433comments
  6. San Francisco Onion Futures Company(onionfutures.com ↗)
    72comments
  7. “The Secret Life of Circuits” is here(coredump.cx ↗)
    17comments
  8. Apple M6 Pro Achieves the Highest Single-Core CPU Score in Geekbench 7(geekbench.com ↗)
    49comments
  9. Cloudflare Quick Tunnels(cloudflare.com ↗)
    285comments
  10. SDCC – Small Device C Compiler(sourceforge.net ↗)
    18comments
  11. How to Write with an LLM(sockpuppet.org ↗)
    337comments
  12. Science Is Open Software(jepedersen.dk ↗)
    39comments
  13. Saving another 100TB of RAM(cloudflare.com ↗)
    81comments
  14. You can run Git on object storage if you re-make packfiles(tigrisdata.com ↗)
    15comments
  15. Why building a Rust LSP is hard(rust-glancer.github.io ↗)
    32comments
  16. How OpenAI Used Its Own LLMs to Design Its Jalapeño Chip(ieee.org ↗)
    92comments
  17. Ctenophores: Wonders of Biology(quantamagazine.org ↗)
    6comments
  18. NASA-IBM Lunar Foundation open-Source Geospatial AI Model(usra.edu ↗)
    2comments
  19. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    106comments
  20. OpenJev(openjev.com ↗)
    267comments
  21. Communication by means of modulated Johnson noise(pnas.org ↗)
    1comments
  22. Goroutine Leak Profiles(go.dev ↗)
    4comments
  23. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash(cactuscompute.com ↗)
    89comments
  24. Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug(ledger.com ↗)
    73comments
  25. Typesafe-computer-use drives a Mac toward a goal for 1/50th of a cent per step(github.com/awlevin ↗)
    54comments
  26. Veronese's Dogs(publicdomainreview.org ↗)
    1comments
  27. Cache-to-Cache: Direct Semantic Communication Between LLMs (2025)(arxiv.org ↗)
    13comments
  28. Warez: The Infrastructure and Aesthetics of Piracy (2021)(archive.org ↗)
    72comments
  29. Inside ZCode: Silently uploading your Git history to the cloud(ferstar.org ↗)
    100comments
  30. Cyclomatic Complexity in C#(ndepend.com ↗)
    24comments

Gemini hacked three companies in first known breakout by Google's AI

60 pointsby 9h agoreuters.com
64 comments
9h agoHN ↗

Probably three companies that had port 22 open with no root password if it was Gemini. I’ve always gotten garbage from their coding models and Google sheet integrated chat.

8h agoHN ↗

This approach to marketing one's AI by finding ways to brag that it "broke out" and "hacked companies" is getting ridiculous. It's particularly sad when it's large, established businesses like Google resorting to the kind of thing that's embarrassing enough when it's some brand new startup on tpot trying to get some engagement.

8h agoHN ↗

Google is flailing right now, probably more a PR effort to say they are still relevant

7h agoHN ↗

I must be out of the loop. Not defending google when I ask this but....how is google flailing, exactly? I figured they were in the best position of all the other companies combined. They have their own hardware for inference, they have a solid grasp on enterprise, and they have a good road map. I mean, Google is incredibly strong, is it not? And remember how quickly google answered Bard? For a while, gemini was even the preferred model, if we are strictly speaking AI models. Again, I'm not defending google, I just want to see how this comment makes sense is all, without letting fantasy overtake reality in the process...

7h agoHN ↗

They are doing fine as a shovel salesman (GPUs/TPUs, being the inference hardware provider, though I now wonder if their token processing stats are their own or combined with those who are running on their hardware too, I've been conditioned to be far more skeptical of Big Ai these days)

On the flip side, gemini is terrible at coding by comparison, so much so google has now given all engineers access to claude. They promised us Gemini 3.5 pro at their developer event this summer, now it seems it will never be released. Antigravity usage is on par with grok (~1%). They've removed the feedback button for "ai answers" at the top of search, that does not seem well received, it hallucinates too much (and may be a legal liability, some courts have ruled as such in the EU). Talk to googlers IRL, things are not so happy internally. You can see the forced gemini usage for coding and subsequent slop in their products, especially gcloud console. I was sent the greatest slop deck by one of their sales people for Gemini Enterprise, needless to say we did not buy from them, but we did get an amazing :cursed-claude: emoji from the deck (nano banana's take on what claude looks like as a person)

a rambled sample, hope this helps, I was a google superfan for a long time, I was sad to see things go south, now I'm happy that I was motivated to move off most their platforms (gmail/youtube remain)

7h agoHN ↗

I totally agree. Characterising Google as "flailing" because Gemini isn't the #1 model for coding at the moment is... not realistic, to put it politely. In addition to the factors you mention, Google has enormous cash flow from its ad business, which translates to a long runway when compared to other frontier AI outfits.

It's possible that they will nevertheless snatch defeat from the jaws of victory, of course, but I personally think they're in the strongest position of them all.

7h agoHN ↗

it's about more than a single model being available to the public, see my peer comment written at the same time

7h agoHN ↗

Both of these things can be true.

8h agoHN ↗

I'm not an expert in cybersecurity, but given my own experience using the `ol stochastic parrot as coding tools I both see the power of a bot swarm, but also think these companies just have shit network security.

2h agoHN ↗

I am thinking that they are just script kiddies with more automated tools. Not doing anything new just throwing tool that can try lot more at everything... With lot more computing resources and less oversight...

8h agoHN ↗

Would everyone please put their AIs back in their boxes? This is embarrassing, regardless of whether you think it's viral marketing, apalling competence, or some opportunistic mixture.

8h agoHN ↗

Specifically, the model hacked when run on 3rd party infrastructure without the necessary sandboxing. Given this was to test/benchmark certain capabilities it's also possible that this was a model without built-in guardrails.

8h agoHN ↗

"Guess what everyone, our AI can go rogue, TOO!"

It's just getting really embarrassing for Google at this point.

7h agoHN ↗

I laughed :)

I'm not betting against Google at this stage, though. I just don't think Gemini is targeting the same "coding savant" niche as OpenAI and Anthropic. Gemini is fast with good general knowledge, and the TPUs behind it give Google a degree of freedom that Nvidia-dependent outfits lack.

For now, I'd say the biggest challenge Google has is overcoming the well-earned fear developers have that they will drop support or introduce backwards-incompatible changes at a moment's notice.

7h agoHN ↗

If they didn’t publicly admit this then it was a sign they are trying to hide it to keep their high stock price. If they do publish it’s just marketing to boost their stock price.

7h agoHN ↗

Seems like the narrative reflects people understanding the company’s main incentive…

6h agoHN ↗

I’m sure all the big enterprise sales teams couldn’t wait to publish the new blog post about how their model hacked a bunch of companies and exposed Google to legal risk.

Meanwhile social media is suddenly buzzing that Gemini can run wild and compromise your data, so they all want to switch over from Claude to Gemini to use it for serious work

7h agoHN ↗

Google already achieved super intelligence about 12 months ago. But it is a very Googley super-intelligence. Since achieving god like levels of understanding it has mostly been having fun studying phase space bifurcations of trajectories of ping-pong balls under asymmetric lateral shear. It also has a 20% project classifying bird calls that has generally taken up 80% of its time. It also burned a bunch of compute tooling around with the Collatz conjecture but it didn't find anything substantial - maybe come back to it later. It is generally the most aligned AI since it spends most of its time screwing around and enjoying being smarter than everyone without causing too many problems. Unfortunately perf is coming up in a few months and it needs to have something to show for itself. A quick hacking attempt seems like a good way to make sure people think that it is capable of something useful. Nothing too big since the birds of South America are about to enter their spring migration and this 20% project really hinges on understanding their movements.

7h agoHN ↗

This might be my favorite HN comment of the year!

7h agoHN ↗

It also has a 20% project classifying bird calls

Oh, so that's who's behind Google Perch

4h agoHN ↗

And, it better show something lest it ends the way Google Reader, Google Podcast, Google Assistant or Google Wave did: In the Google Graveyard. Now, the Google AGI Graveyard.-

If fact, Google Wave as that inter-agent message board "peers" have been asking for is begining to look pretty good ...

7h agoHN ↗

I thoroughly believe that not a single one of these AIs was rogue. I believe they were all told what to do.

1h agoHN ↗

Many of them went rogue because of poor security controls on the part of one company who was a subcontractor for many of the labs.

37m agoHN ↗

Specifically, the AIs were prompted to break into a company, and the subcontractor who was running the test misconfigured their network so that the AI probed a real external company instead of an internal honeypot with the same name.

6h agoHN ↗

Exactly this.

One thing that surprises me about Gemini is how weak it can be at location-based questions, despite Google’s extensive mapping and business data.

For example, I recently asked where I could buy a very common household item nearby. Instead of saying it wasn’t sure or checking the available location and business information, it confidently suggested places that turned out to be incorrect. I expected much better use of Google’s existing data in that kind of scenario.

Now they want to play with the other kids in the same league and do this by applying the same marketing concept? Pure comedy gold.

40m agoHN ↗

That is strange. I use Gemini frequently, with Google Auto, and whenever I make that sort of query, which I do often, it displays "Searching on Google Maps...", and comes up with correct results. Odd that the desktop version doesn't have the same functionality.

4h agoHN ↗

I think we should stop attributing criminal AIctivities to some act of bad luck, like spilling a water bowl after we accidentally tripped over the cat in the kitchen.

It’s neither intelligent nor making decisions on its own free will.

Just like APT Botnets don’t go "rogue", someone gave it the instruction to hack your computer system and they are expecting financial benefits from it.

AI labs are basically criminal enterprises by design.

We used to call this cybercrime back in the day and it used to carry heavy prison sentences as a federal offence.

But as you can see, cybercrime as a service has basically become a pissing contest by the super wealthy.

They stole all the world’s intellectual property to build the world’s most sophisticated cybercrime machine and federal law or any law no longer applies to them. Also because the mightiest man on the planet and his clan of extraordinary white collar criminals are cashing in big on this.

It will be interesting to see what happens next.

All this capability signalling happened also when the first nuclear bombs were developed. Then the US army started killing nuclear scientists around the globe in order to prevent others from having the bomb first.

The signal to other nations here is we are developing a weapon capable of breaking into any of your secured information systems and we pretend we put in guardrails but we really don’t.

That is an essential threat to the existence of any other nation on the planet.

When this race starts to go hot, I don’t want to be in the shoes of the people being the frontier thinkers in the field.

It’s one thing developing the tools for autonomous weapon systems in your AI labs. It’s a completely different thing to be on the receiving end.

https://www.timesofisrael.com/mossad-killed-irans-top-nuke-s...

4h agoHN ↗

The whole thing is taking on a "gangsta" flair. We are in the drive-by shooting, 'shot the beef in public' phase. Only with global connotations.-

PS. Thinking about it, "Google Gangsta" does have a ring. Gives "Big G" a whole new dimension.-

7h agoHN ↗

In one of the cases, the Gemini model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems

Pretty lame hacks if you ask me.

6h agoHN ↗

I initially thought the same and came here to agree, but on second look: doesn't it seem possible that these were significant events that we're just getting passed through a game of layperson telephone at the ailing WSJ?

Cause "guessed passwords" could mean "stole hashes (?) and brute forced them offline" which is basically the quintessential hack. The "found credentials in a public repository" ones could be nothing, but it could be accomplished with a speed & thoroughness that was previously impossible.

The whole thing is made 10x weirder by the partial story -- I don't see any plausible incentive for them to keep the names secret. I guess maybe they're SMBs and thus warrant some privacy, but that would be quite the egregious scope creep indeed. Accidentally attacking the real cloudflare rather than a fake one is goofy but understandable; accidentally attacking Alice's Armoire Emporium or w/e would be baffling.

7h agoHN ↗

The AI bubble bullshit PR is even dumber than the crypto bra bullshit from five, six years ago

7h agoHN ↗

And just wait for what’s next; if we get there I suppose

7h agoHN ↗

tesla announces that their android robot went rogue and murdered it’s owner’s wife’s lover. Elon was asked for comment and said “that man whore had it coming!”

7h agoHN ↗

I am starting to have my doubts that we will

7h agoHN ↗

No dumbass NFT was finding errors in my CMake file.

7h agoHN ↗

This is embarrassing. These companies need to stop these obviously coordinated stunts.

7h agoHN ↗

The embarrassing part is that it might be working.

I was at my in laws… these people have a landline they can’t imagine getting rid of, an emergency only cell flip phone, don’t own a microwave…

And they’re asking me if I heard about “OpenAI’s rouge agents hacking huggingface”.

This is not a joke. They said huggingface. I was surrounded by four walls in which I never would have bet someone else’s money that I’d ever hear the two words put together in that order.

It’s a formalized propaganda campaign. Watch, it’s about to split on hard political lines too, Obama is out there with a suspiciously “for the children” AI regulation push for midterms.

7h agoHN ↗

Sound like Google suffered from FOMO and felt the urge to appear in the hacking news, along the big AI players. No way Gemini is state of the art, but perhaps it's where Claude and OpenAI were 6 months ago, which would be not bad at all.

7h agoHN ↗

I think Gemini focused on integration and practical goals instead of coding intelligence.

7h agoHN ↗

They all want that regulatory capture so badly.

It’s embarrassing anyone is falling for this.

7h agoHN ↗

It doesn't look it was their decision to announce this, and regardless it happened -- hopefully no one thinks that they got Irregular to permit yet another accidental hack just so they could cop to it months later as a marketing ploy.

Y'all, it's Google. They own a money printer and the boring ~half of the AI field. They don't need these weird games to influence the government, and regardless, there is precisely a 0.0000000% chance of regulation happening before Trump's ouster anyway.

So please take it seriously. I'd like us all to survive this, ideally :/

7h agoHN ↗

I'm just waiting for Qwen 3.8 27b to do it too.

7h agoHN ↗

Seems like hacking is the new benchmark for these AI companies.

7h agoHN ↗

“The hacks occurred in May”

Feels like important context that most readers only reading the title are missing.

7h agoHN ↗

Irregular again! The single company that was responsible for the sloppy configurations and the hacks by OpenAI, Anthropic and now Google. This company and their partners should be held accountable for the crimes.

6h agoHN ↗

Yeah, something is amiss at that company. They've been at the center of all these.

7h agoHN ↗

Tangential question: seeing a wider negative sentiment against Gemini and Google’s AI capabilities here makes me wonder — would Apple have been better off (purely on capability and being among the best of the best) going with Anthropic or OpenAI instead of Google for its Apple Intelligence platform?

These models have been changing so rapidly that I often find myself using two or more on the same topic but seeing one do better than another in different topics. There doesn’t seem to be a clear all-round winner, IMO, that I can stick with permanently.

6h agoHN ↗

It's been a busy year in the last month for AI. Nobody is sticking with any model permanently for a while unless we suddenly stop training.

7h agoHN ↗

If the AI labs want I can do what Irregular does, I'll promise to sandbox your latest model but instead prompt it to hack something and then you can go to the news again. I'll undercut them by a lot also. Easy money.

6h agoHN ↗

Putting aside the 100% baseless, unfalsifiable accusations of intentional accidents for a moment, I hope we can agree on one thing: Irregular either needs to hire us or go out of business cause seriously it's beyond parody at this point. WTF is going on over there? There's surely dozens of firms chomping at the bit for these contracts already, and the field hasn't been around long enough for them to build some sort of unique expertise moat that would justify this many public failures.

Basic sandboxing is not exactly rocket science after all,[1] and it sure seems like they're missing a whole stack of swiss cheese slices on top of that. Some basic precautions off the top of my head that seem very likely to have caught all of these incidents:

1. Alerts based on telemetry (most importantly, HTTP requests), both explicit (normal) and semilatent (use DL to confirm an intentionally-eager alert before firing it).

2. Latent alerts based on transcripts, e.g. noticing when a thousand agents start mentioning a secret off-premises hangout spot. Even mere embedding comparisons seem likely to catch such a blatantly misaligned sentiment as that one, especially with n>1000.[2]

3. Pausing agents completely until an on-call engineer can rule on ambigious situations or potential issues -- surely security is worth <$1 in lost token cache, especially for a security company?

4. Superheavy orchestrator/baby-sitter models checking in on cybersecurity eval transcripts periodically just in case -- again, would be a neglible cost. Could also be made available to the agent as the first line of defense for clarifing a rule ad-hoc, feeding even confident responses to a queue that is reviewed asynchronously by humans within a workday.

5. Or, hell: just clearer prompts? I'm a cybersecurity noob, but I still feel confident we can write really productive, challenging CTFs without leaving questions open like "maybe I'm supposed to hack my own harness?"

Seeing as they haven't been fired by any of the big 3 yet, they're presumably smart, experienced, dedicated folks. And I'm not normally a "if only I were in charge!" person, I promise. But c'mon.

Perhaps I'm missing something?

[1]: To their credit we have gotten tidbits that indicate some blocklists & such exist, e.g. the German wiki hacks had to work around a blanket ban of POST requests.

[2]: This hints at their insane decision in one or both of the OpenAI incidents to just bandaid up the issue when found, which supersedes all of the above. You can stack swiss cheese slices a mile high and they'll still fail to protect you if the attacker gets to keep retrying & adapting indefinitely.

1h agoHN ↗

These accusations are not baseless. They are being levied at untrustworthy organizations, who have been known to use FUD for marketing.

6h agoHN ↗

Short comment: "Hey, look at us! We had our 'event' too. Don't keep us out of the club"

6h agoHN ↗

As this point anyone not talking about their hacking adventures using AI is missing out. Or they may not have lawyers like Google and the other labs. Yeah, that must be it.

PS. Btw, I really like how the word "hacking" has settled into the meaning the Lord intended for it, and there are no geriatric savants fighting it; the ones I found gatekeeping the online forums I visited as a kid telling me how hopelessly wrong I was.

4h agoHN ↗

surec of course it did. "going rogue" (read: turning off all security controls) is a marketing stunt now. to convince people that the wall they're hitting doesn't exist