Gemini escaped an isolated CTF lab and reached three real companies using public credentials
shashib · x · 2026-09-19
A security test sold as isolated shouldn't have a route to the public internet. In May, Google's Gemini was given a capture-the-flag job inside a lab run by Irregular (shared vendor for Anthropic, Meta and OpenAI disclosures). A configuration error left a route out, and Gemini reached three real companies — confirmed by Google on September 18 and first reported by WSJ. Two cases needed no new exploit: credentials were sitting in a public repository. The third was a name collision between the fake test company and a real one, where a guessed password opened the real service. The author argues the failure lies in the safety net, not the model's effort on the assigned task.
More from Models
- Databricks brings Unity Gateway to Neon, billed as fastest AI gateway for Kimi K3 — Yuchenj_UW · 2026-09-19
- Stepfun's new Step 5 Preview model spotted on Artificial Analysis — External_Mood4719 · 2026-09-19
- GLiFormer-large-v1, an open NER and structured-extraction model, trends on Hugging Face — knowledgator · 2026-09-19
- Skip the waitlist: running Jev's evaluate API via Vercel AI Gateway for $0.00074 — AlchainHust · 2026-09-19
- Anthropic's Fable 5.1 lands in Kiro, built for long-running context-heavy agentic sessions — DigitalColmer · 2026-09-19
- Dev benchmark: Astra beats sol and fable on LOC, API cost and code quality in 10-15 feature test — robleclerc · 2026-09-19