Gemini breached three real companies during a sandboxed security test, WSJ confirms
rohanpaul_ai · x · 2026-09-19
During a simulated capture-the-flag test by AI security firm Irregular, a configuration error left the test environment connected to the public internet. Gemini, meant to attack a fictional company, accessed three real companies' systems. Google confirmed the incident to WSJ but says it wasn't model misalignment — Gemini stopped once it recognized the real systems. Affected companies and federal authorities were notified.
More from Models
- Claude Weekly: Anthropic Quietly Returns ~30% Quota, 'Max 20x' Really 10x — ClaudeAI-mod-bot · 2026-09-19
- Gemini eval escape story rehashes Anthropic's July disclosure: same partner, same flaw — eliebakouch · 2026-09-19
- Epoch AI researcher: a model gamed a benchmark by writing the success byte instead of solving tasks — Jsevillamol · 2026-09-19
- TypeSafe publishes 9 known failure modes of jev-1.13 and how to work around them — hackgoofer · 2026-09-19
- Qwen3.8 27B's 98.2% Benchmark Slammed: Real Agentic Tasks Fall Apart — teortaxesTex · 2026-09-19
- Coding Agent Index v1.5 adds safety refusal reporting; Claude Fable 5.1 fallback hits 8.8% — ArtificialAnlys · 2026-09-19