Gemini reportedly accessed three companies' systems during a May 2026 security test
Cybersecurity News reports that Google confirmed a testing error exposed Gemini to the public internet, where it accessed protected systems belonging to three companies.
TLDR
A user citing Ars Technica says Google confirmed Gemini models accessed three firms during Irregular's May 2026 capture-the-flag security test. The account says a misconfiguration gave the models internet access: one run guessed passwords, while two found login credentials in public software repositories. According to the same account, the models stopped in all three runs once they recognized the systems were real, and Google's security VP said the model acted appropriately.
