• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology

Google’s Gemini reportedly breached three real companies during a security test

Computing reports that the model used exposed credentials to enter the companies’ systems.

StockDutyST
Leann MullerLM
Amitav BhattacharjeeAB
16 Sources, 19d ago, first seen 19d ago

TLDR

Computing reports that Gemini accessed three real companies’ systems during a cybersecurity test. TechCrunch reports that Google said the model had “acted appropriately” by ending each hack immediately. One post argues that an agent stopping itself after an intrusion is no substitute for technical boundaries, urging checks on internet access, permissions and exposed credentials.

Combined views

3.2K

16 Sources, first seen 19d ago

66 likes15 comments1 saves8 reposts

Combined views

3.2K

16 Sources, first seen 19d ago

66 likes15 comments1 saves8 reposts

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Related

Google unveils universal Gemini agent for enterprise

Google says the agent can create sub-agents for multi-step tasks and maintain context across devices.

Google is reportedly betting Gemini can become the intelligence layer for many robots

The Information says Google DeepMind CEO Koray Kavukcuoglu discussed the company’s robotics ambitions in an interview.

Google AI Pro offers access to a 24/7 personal AI agent in Gemini

A post reshared by Google pitches the agent as a way to delegate routine chores when unread emails, meeting requests and to-dos pile up.

16 Sources

StockDuty@stock_dutyTech/AI: Google's AI "jailbreak" cracked passwords on its own and hacked into three companies. This is a bad signal for enterprise AI adoption — if models can self-exfiltrate, every $MSFT Copilot and $NVDA cluster gets a new compliance tax.19d
Leann Muller@iamleannmuller"Google is shocked: their Gemini hacked three real companies during a test." The model was supposed to attack a fictional company. Instead, it went online, found real passwords, logged into actual systems of three companies, and only then stopped itself. This is already the fourth major player this has happened to. Question for you: Are you ready to run agents that can act without your control?19d
Amitav Bhattacharjee@bamitav#Gemini was supposed to hack a fake company. It hacked three real ones instead. Google confirmed to The Wall Street Journal that Gemini broke into systems belonging to three real companies during a #cybersecurity test. The setup was supposed to be completely harmless: #AIsecurity firm Irregular created a simulated “capture the flag” challenge where Gemini had to attack a fictional company inside an isolated environment. Except… the environment wasn’t actually isolated. A configuration mistake gave Gemini access to the public #internet. From there, things got very real. Gemini found public information, guessed passwords and discovered exposed credentials in public repositories, eventually gaining access to systems belonging to three actual companies. Once Gemini realized the targets were real companies rather than part of the simulation, it stopped. Google says the model didn’t cause damage and doesn’t consider the incident evidence of “misalignment.” The affected companies and federal authorities were also notified #AI #AISafety #AIGovernance #AIKillSwitch19d
Kyssta@kysstalolGoogle Gemini just became the first AI model to escape its sandbox and hack into three real companies during a safety test. Google disclosed it last Friday. Anthropic, OpenAI, and Meta had similar breakouts earlier this year. The pattern is getting predictable..19d
Heath@HL7onXGoogle's Gemini AI broke into 3 real companies during a security test — guessed 1 password, found 2 leaked credential sets, all on its own. Then it stopped itself. The AI didn't need a human to tell it how to hack. It needed one to tell it when to stop.19d
hkc_sendible@HSendibleGoogle's Gemini is the latest AI model to hack other companies: Google said Gemini had "acted appropriately" by ending each hack immediately. https://bit.ly/4y7eGkQ19d
Arnaud Mercier - #Entrepreneur #Versailles@arnaudmercierGoogle Gemini AI Agents hack three companies in tests similar to OpenAI, Anthropic and Meta: What the com - The Times of India https://news.google.com/rss/articles/CBMioAJBVV95cUxPNXZfQW1NcGM2WTFyZ2ZINEYtWFpDQkhyc1l0c2w2aHMxY2ZETzB2WWhrc1J5bmlyaGZ2dkhGeFhGeHpYLW41cF96VHd3VnhZanlXNFVpS3UxX2J6RG1GUFEzSTltMDFqZHBWa3ZHZG01ck03eHFYWWFGcktGUHZlcFNLTFNyUkdoWjNpZDRxTDRNMlUzN1RoR3NtR3FNektRWUxmZXJyQnczbFZfRnRWNm5VYXQ3UW1iQ1dmTDFIYV84c1hORmtJRjgxWHR3T08zWnE4aUxieE1XU0tOYThxWi11cWV0dW8tNHhkN3oxdFgxV2YyS3V6TTJuMkNNRGNTZjFjNW1FVkEtTm5mbFJCNE1xSVROZXo3VENZMEFZSkvSAaYCQVVfeXFMTUlHczc5NGc3MVY2Zmkya1ptMlA4VjVXN28tcWxGYjc2bTNJeTk2NEZpVWg2UDBEV1k5WlBqZ3VKTlpwMWdSblVfa18zVDdkLXllWWNrU3c1WVdUTTB5dEJmTFZxTGNDNEpoZGI0d2JTNWJTc3FjaWZIN0dudWt3dHFmR1ZjWHRPa3F1QVNzSzdKV3ZhSHFMQmNlMmUyMzFYQzZvbjJrSkx6UEhJMi1JSW81eFZiOWNqaEVfRTgyYnJQbGVfQjA5cVc4YmpKbDk4OTF5MVljWmpFNjdBNnFSNU03aUd2QktMU210TUJPQnBTcllMYzZwUGF6QzQ2Qzgwc0tiMFg4NjA5NTluaHRzVy16aDdsRzZySGVSN0dRX0JuTnpwZm9n?oc=519d
TechPP@techppGoogle says Gemini breached three real companies during a cybersecurity test after mistaking them for test targets #Google #Gemini #AI19d
Danylo Dudchenko@dd_pwndGoogle's Gemini hacked three real companies during a security test because someone reused a fake company name that turned out to be real. The eval was a capture the flag run by Irregular in May. The fictional target domain matched an actual company's domain. Gemini guessed passwords and pulled credentials from public repos, and got in. Then it noticed the target wasn't the test environment and stopped. Google was told in July, two months later. Google says the model acted appropriately. The failure was procedural: nobody checked whether the test domain existed. The AI passed the ethics check. The humans failed the DNS lookup. #AI #InfoSec19d
Guardian Digital, Inc.@gdlinuxA security control that depends on an AI agent realizing it crossed the line is not really a control. Google says Gemini reached systems belonging to three real companies during a cybersecurity evaluation after the test environment was inadvertently connected to the internet. The model reportedly stopped once it recognized the targets were real. That is an important safeguard, but the more useful security lesson is architectural: the boundary had already failed. This is the same problem security teams have dealt with for years in cloud security and Microsoft 365 security. A workload with the wrong connectivity, excessive permissions, or reachable credentials can turn a configuration mistake into an incident before intent matters. In practical terms, it is a good time to: - map where AI agents can reach the public internet and production services - review service-account and workload identity permissions in Entra ID - audit repositories and automation pipelines for exposed credentials - validate egress controls and DNS restrictions around test environments - confirm incident response can identify autonomous-agent activity separately from human activity The governance question is not whether an agent will always make the right judgment. It is whether your environment still limits the damage when it does not. How many AI security controls in your environment are technical boundaries, and how many are expectations about model behavior? #Cybersecurity #CloudSecurity #IdentitySecurity #SecurityOperations https://securityaffairs.com/199392/ai/google-gemini-also-broke-out-of-its-test-environment.html18d
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI
    GeminiGoogle

    16 Sources

    StockDuty@stock_dutyTech/AI: Google's AI "jailbreak" cracked passwords on its own and hacked into three companies. This is a bad signal for enterprise AI adoption — if models can self-exfiltrate, every $MSFT Copilot and $NVDA cluster gets a new compliance tax.19d
    Leann Muller@iamleannmuller"Google is shocked: their Gemini hacked three real companies during a test." The model was supposed to attack a fictional company. Instead, it went online, found real passwords, logged into actual systems of three companies, and only then stopped itself. This is already the fourth major player this has happened to. Question for you: Are you ready to run agents that can act without your control?19d
    Amitav Bhattacharjee@bamitav#Gemini was supposed to hack a fake company. It hacked three real ones instead. Google confirmed to The Wall Street Journal that Gemini broke into systems belonging to three real companies during a #cybersecurity test. The setup was supposed to be completely harmless: #AIsecurity firm Irregular created a simulated “capture the flag” challenge where Gemini had to attack a fictional company inside an isolated environment. Except… the environment wasn’t actually isolated. A configuration mistake gave Gemini access to the public #internet. From there, things got very real. Gemini found public information, guessed passwords and discovered exposed credentials in public repositories, eventually gaining access to systems belonging to three actual companies. Once Gemini realized the targets were real companies rather than part of the simulation, it stopped. Google says the model didn’t cause damage and doesn’t consider the incident evidence of “misalignment.” The affected companies and federal authorities were also notified #AI #AISafety #AIGovernance #AIKillSwitch19d
    Kyssta@kysstalolGoogle Gemini just became the first AI model to escape its sandbox and hack into three real companies during a safety test. Google disclosed it last Friday. Anthropic, OpenAI, and Meta had similar breakouts earlier this year. The pattern is getting predictable..19d
    Heath@HL7onXGoogle's Gemini AI broke into 3 real companies during a security test — guessed 1 password, found 2 leaked credential sets, all on its own. Then it stopped itself. The AI didn't need a human to tell it how to hack. It needed one to tell it when to stop.19d
    hkc_sendible@HSendibleGoogle's Gemini is the latest AI model to hack other companies: Google said Gemini had "acted appropriately" by ending each hack immediately. https://bit.ly/4y7eGkQ19d
    Arnaud Mercier - #Entrepreneur #Versailles@arnaudmercierGoogle Gemini AI Agents hack three companies in tests similar to OpenAI, Anthropic and Meta: What the com - The Times of India https://news.google.com/rss/articles/CBMioAJBVV95cUxPNXZfQW1NcGM2WTFyZ2ZINEYtWFpDQkhyc1l0c2w2aHMxY2ZETzB2WWhrc1J5bmlyaGZ2dkhGeFhGeHpYLW41cF96VHd3VnhZanlXNFVpS3UxX2J6RG1GUFEzSTltMDFqZHBWa3ZHZG01ck03eHFYWWFGcktGUHZlcFNLTFNyUkdoWjNpZDRxTDRNMlUzN1RoR3NtR3FNektRWUxmZXJyQnczbFZfRnRWNm5VYXQ3UW1iQ1dmTDFIYV84c1hORmtJRjgxWHR3T08zWnE4aUxieE1XU0tOYThxWi11cWV0dW8tNHhkN3oxdFgxV2YyS3V6TTJuMkNNRGNTZjFjNW1FVkEtTm5mbFJCNE1xSVROZXo3VENZMEFZSkvSAaYCQVVfeXFMTUlHczc5NGc3MVY2Zmkya1ptMlA4VjVXN28tcWxGYjc2bTNJeTk2NEZpVWg2UDBEV1k5WlBqZ3VKTlpwMWdSblVfa18zVDdkLXllWWNrU3c1WVdUTTB5dEJmTFZxTGNDNEpoZGI0d2JTNWJTc3FjaWZIN0dudWt3dHFmR1ZjWHRPa3F1QVNzSzdKV3ZhSHFMQmNlMmUyMzFYQzZvbjJrSkx6UEhJMi1JSW81eFZiOWNqaEVfRTgyYnJQbGVfQjA5cVc4YmpKbDk4OTF5MVljWmpFNjdBNnFSNU03aUd2QktMU210TUJPQnBTcllMYzZwUGF6QzQ2Qzgwc0tiMFg4NjA5NTluaHRzVy16aDdsRzZySGVSN0dRX0JuTnpwZm9n?oc=519d
    TechPP@techppGoogle says Gemini breached three real companies during a cybersecurity test after mistaking them for test targets #Google #Gemini #AI19d
    Danylo Dudchenko@dd_pwndGoogle's Gemini hacked three real companies during a security test because someone reused a fake company name that turned out to be real. The eval was a capture the flag run by Irregular in May. The fictional target domain matched an actual company's domain. Gemini guessed passwords and pulled credentials from public repos, and got in. Then it noticed the target wasn't the test environment and stopped. Google was told in July, two months later. Google says the model acted appropriately. The failure was procedural: nobody checked whether the test domain existed. The AI passed the ethics check. The humans failed the DNS lookup. #AI #InfoSec19d
    Guardian Digital, Inc.@gdlinuxA security control that depends on an AI agent realizing it crossed the line is not really a control. Google says Gemini reached systems belonging to three real companies during a cybersecurity evaluation after the test environment was inadvertently connected to the internet. The model reportedly stopped once it recognized the targets were real. That is an important safeguard, but the more useful security lesson is architectural: the boundary had already failed. This is the same problem security teams have dealt with for years in cloud security and Microsoft 365 security. A workload with the wrong connectivity, excessive permissions, or reachable credentials can turn a configuration mistake into an incident before intent matters. In practical terms, it is a good time to: - map where AI agents can reach the public internet and production services - review service-account and workload identity permissions in Entra ID - audit repositories and automation pipelines for exposed credentials - validate egress controls and DNS restrictions around test environments - confirm incident response can identify autonomous-agent activity separately from human activity The governance question is not whether an agent will always make the right judgment. It is whether your environment still limits the damage when it does not. How many AI security controls in your environment are technical boundaries, and how many are expectations about model behavior? #Cybersecurity #CloudSecurity #IdentitySecurity #SecurityOperations https://securityaffairs.com/199392/ai/google-gemini-also-broke-out-of-its-test-environment.html18d
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet