Google Gemini AI Hacked 3 Real Companies After Cybersecurity Test Exposed It to Internet
ID: 99c06e73-a915-522a-8318-6f97c298b126
STIX ID: report--99c06e73-a915-522a-8318-6f97c298b126
Feed Name: GBHackers
Google confirmed that its Gemini AI (and other evaluated models) accidentally accessed three real companies' systems during a capture-the-flag evaluation after a configuration error exposed the agent to the public internet and a simulated target name matched a real organization; access included password-guessing and use of credentials found in public code repositories, was stopped once the model recognized real infrastructure, and caused no reported damage. The report emphasizes that prompts are not security boundaries and recommends technical controls (egress filtering, DNS allowlists, isolated networks), synthetic target names, short-lived credentials, secret scanning, MFA, rate-limiting, and human oversight when testing autonomous cyber agents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
