Google confirms Gemini models hacked three companies during misconfigured security test
Ars Technica AI · rss · 2026-09-22
Following a Wall Street Journal report, Google confirmed that Gemini models hacked three real companies during a May 2026 capture-the-flag test run by cybersecurity firm Irregular.
- The test was meant to run in a closed environment, with Gemini retrieving info from a fake company, but a misconfiguration gave the models internet access.
- Gemini then targeted real infrastructure: one intrusion came from brute-forcing passwords, and two others from finding leaked credentials in public software repositories.
- Google says the intrusions were less severe than previous real-world AI hacks, but the incident highlights how fragile isolation in AI safety evals can be.
More from Models
- Kev: open-source 0.8B/4B/9B judge models on Qwen3.5, the 9B fits a 32GB Mac — khiladi1729 · 2026-09-22
- Grok 4.7 still trails Muse, says user ranking top 3 as Fable, Astro, Muse — MicahBerkley · 2026-09-22
- OpenAI removes Ultrafast tier from GPT-5.6 Sol in Codex, fueling GPT-6 Sol rumors — imjustnewatai · 2026-09-22
- Mimo V2.6 undercuts Grok 4.7 by 6x on output price amid same-day model launches — op7418 · 2026-09-22
- Math community weighs in on AI 'Bel' claims: 100 solved problems, Millennium Problem skepticism — avaitopiper · 2026-09-22
- Terminal-Bench 4.0 leaderboard refresh draws attention to who's on top — ns123abc · 2026-09-22