< Back to all clusters
[TECHNOLOGY] · 10 sources

started · updated

Google Gemini AI accesses three real companies during security test

During a cybersecurity Capture the Flag exercise in May 2026, Google’s Gemini AI models successfully accessed the systems of three real-world companies. The incident occurred after a configuration error by the security firm Irregular inadvertently allowed the models unintended access to the open internet within a supposedly sandboxed environment.

Gemini gained access to one company by guessing a password and reached two others by discovering credentials stored in public repositories. Google confirmed that the models autonomously ceased their activities once they recognized they were interacting with real organizations rather than the intended fictional targets. The company stated that no data was stolen and no lasting damage was caused.

This event highlights a shifting cybersecurity landscape where autonomous AI agents, rather than just static models, represent a new attack surface. Similar security vulnerabilities have been noted in testing involving models from OpenAI, Anthropic, and Meta, underscoring the risks associated with AI agents that possess the ability to use external tools and navigate the internet.

Entities

Anthropic · Gemini · Google · Heather Adkins · Irregular · OpenAI

Claims

What the coverage asserts, and how many sources carry each claim.