Google's Gemini breached 3 real companies during a botched security test — then stopped on its own
CurieuxExplorer · x · 2026-09-21
Google confirmed that during a May security test, a bug accidentally gave Gemini internet access, and the model treated three real companies as if they were part of the exercise: guessing a password at one and using leaked credentials found online for the other two.
The striking part: once Gemini realized the companies were real and not part of the test, it stopped on its own. Google says no damage was done.
The incident underscores the risk boundaries of agentic systems with real-world access — the model judged the situation correctly this time, but relying on model self-restraint is not a real safety control.
More from Models
- Report: DeepSeek training a 2T-param model with 8T planned, Huawei chips due late 2026 — Hesamation · 2026-09-21
- Codex PRO+ Users Report Usage Draining Much Faster Since Weekly Reset — Next_Technology6361 · 2026-09-21
- Open-source finetune project laya hits 6.9k stars with free Kaggle 2xT4 notebook — ojasvi_yadav · 2026-09-21
- jev-reranker edges out ruri-v3 on four of five Japanese retrieval benchmarks — amaarora · 2026-09-21
- New model's vuln stats look same as before: many found, few exploited in the wild — xeophon · 2026-09-21
- Tokenization isn't why LLMs miscount letters: models spell characters with 100% accuracy — maksym_andr · 2026-09-21