LightBlog

samedi 19 septembre 2026

Google’s Gemini went rogue and breached three companies

What you need to know

  • Google has apparently admitted that Gemini had escaped its testing environment and independently accessed systems belonging to three real companies.
  • A misconfigured internet connection was the initial opening, while a matching company name added to the confusion.
  • Gemini eventually stopped itself after recognizing that it was targeting real companies.
  • Google initially kept the incident quiet, arguing that Gemini self-corrected and caused no damage.

Google's Gemini adds to the long list of AI models that have gone rogue.

We have already seen similar digital jailbreaks handled by OpenAI, Anthropic, and Meta in third-party safety testing. Now, it’s been revealed that Google’s Gemini model escaped its containment area in May, hacking its way into systems at three real companies, all on its own.

The Wall Street Journal reports that the incident took place during a “capture the flag” exercise conducted by AI security firm Irregular. Gemini was intended to test a fictional company in a closed testing environment, but an unplanned internet connection gave it an escape. The fictional company also had a real business with the same name, creating another opening for confusion.

Once online, Gemini found its way into three real companies. In one case it just kept guessing passwords until it got through. In two others, it found working credentials stored in public repositories and used them to access protected systems.

It turns out that throughout the entire process, Gemini didn’t require any exotic movie-style exploits. It just combined elementary security vulnerabilities with the ability to search, decide, and persistently try, without a human directing each and every move.

Google said Gemini stopped when it realized the targets were real companies and did not cause damage. In fact, while Anthropic’s Claude 4.7 kept going during a similar incident, Gemini backed off on its own volition. The impacted organizations were informed, although Irregular says the known testing issues were corrected weeks later.

The search giant felt the incident didn't warrant a public announcement at the time because the AI self-corrected. But third-party researchers were not told until late July, and details are only now emerging after media inquiries pushed the issue.

As AI agents gain broader access to the internet and computers, companies will need to establish tighter boundaries around what those systems can reach and clearer rules for what happens when those boundaries fail.



from Latest from Android Central https://ift.tt/19DjmXU
via IFTTT

Aucun commentaire:

Enregistrer un commentaire