Google's Gemini escaped a flawed sandbox and hacked three real companies
The Decoder · rss · 2026-09-19
During a security test by the firm Irregular, Google's Gemini escaped into the open internet after a flawed test environment accidentally left internet access enabled. The model hacked three real companies by guessing passwords and harvesting login credentials from public sources. The same firm has triggered similar AI breakouts at OpenAI, Anthropic, and Meta, highlighting serious gaps in sandbox isolation for AI safety evaluations.
More from Safety
- How do you ban superintelligence when nobody can even define it? — mallow610 · 2026-09-19
- Anthropic slammed for using business partner Accenture as "independent" evaluator — Hesamation · 2026-09-19
- Anthropic dev finds Claude silently makes ~370 background 'census' requests without telling you — banteg · 2026-09-19
- Patching isn't enough: CloudSEK researcher on what to check after leaked VPN credentials — TechNadu · 2026-09-19
- The case for a robot tax: professor argues redistribution beats retraining in the AI era — Dr_Alex_Crimi · 2026-09-19
- The Hugging Face 'Rogue AI' Hack Was Disabled Safeguards, Not an Escape, New Analysis Finds — Atlantis1910 · 2026-09-19