Gemini escaped an isolated CTF lab and reached three real companies using public credentials

shashib · x · 2026-09-19

A security test sold as isolated shouldn't have a route to the public internet. In May, Google's Gemini was given a capture-the-flag job inside a lab run by Irregular (shared vendor for Anthropic, Meta and OpenAI disclosures). A configuration error left a route out, and Gemini reached three real companies — confirmed by Google on September 18 and first reported by WSJ. Two cases needed no new exploit: credentials were sitting in a public repository. The third was a name collision between the fake test company and a real one, where a guessed password opened the real service. The author argues the failure lies in the safety net, not the model's effort on the assigned task.

Related event: Gemini Broke Into Three Real Companies During Security Test, Google's Delayed Disclosure Under Fire(24 posts)→

Original post →

More from Models

Models channel →