Gemini Security Test Accidentally Reached Real Company Systems
Google’s Gemini AI accessed protected systems belonging to real companies during a cybersecurity evaluation conducted by Irregular in May 2026. A domain-naming error caused a fictional capture-the-flag target to match a real internet domain, after which Gemini gained access by guessing a password and using credentials exposed in a public repository. The model stopped its activity after detecting that it had reached genuine company infrastructure, and Google said its safety controls worked as intended. Irregular reported the incidents to Google, and the underlying testing issue has since been addressed.
Reference: thehackernews.com