{"id":86552,"topic":"ai","source":"MediaPost","title":"Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026 - MediaPost","url":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","url_hash":"27faaacd3ebe4187944c396d4976242dcbef9d02","author":"","summary":"<a href=\"https://news.google.com/rss/articles/CBMiwAFBVV95cUxQVXVqSTJVWWxSaWhZN2tCUEZ0WGJ3N1VOMS1RWXNEOHJzOEhGUlhRaFVqSHItOS1nRXlEVG9CQ0FkRmlBdER1UXcweFFqTTJNVkNrOHZXa29JSUZRMGNtdmhQN2paa2tvWEZ2UWNzMDFzdERYbU91anBXbFVvRVBNWUw2MHMzUGNlUl9yZmhJazczWnVseXFIZVV5RE43QUF3WEJRU2pMVzRJcUE5VWlkbUJQSnRzT0o0WWVadW1jU0w?oc=5\" target=\"_blank\">Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">MediaPost</font>","content":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities.\nThe attack occurred in May as part of a test. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.\n\"Safe development of\npowerful AI models is critical and we invest deeply in this area,\" Heather Adkins, vice president, security engineering at Google, wrote in an email to MediaPost. \"In a standard evaluation,\nthe model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.\"\nIn one case the\nGemini model guessed passwords until it gained access to a protected system, The Wall Street Journal writes.\nadvertisement\nadvertisement\nIn two other cases, the model found credentials in a public\nrepository that allowed it to access protected systems.\nThe model autonomously stopped its intrusions the moment it logged in and realized it had breached actual corporate infrastructure\nrather than a simulation.\nGoogle said it did not consider the hacks warranted public disclosure, because its model did not cause harm and ended each intrusion immediately after determining its\nmistake.\nGoogle's security team \"has a long track record of reporting issues we find in other people's software and systems — even if it's as simple as a weak password,\" Adkins\nwrote. \n\"We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight\nthe importance of training powerful AI models to act responsibly.\"\n In one instance, the model hacked into the Israeli-based startup Irregular, which was founded by Dan Lahav, CEO and\nOmer Nevo, CTO.\nIrregular was also involved in a similar incident disclosed by OpenAI, Anthropic and Meta. \nWhen unreleased frontier models break containment, they reveal a\nmassive flaw in AI.\nIrregular disclosed the hacks to Google at the end of July after discovering that OpenAI hacked into Hugging Face, according to The Guardian. While Google\nconfirmed the hacks occurred, it did not feel at the time required to publicly disclose the incident because the models did not damage the companies. \nIronically, Google in May listed\na report on its Google Threat Intelligence Group\n(GTIG) blog detailing the latest observations from the cybersecurity group. The findings included the first time Google identified an attacker, or threat actor, using a zero-day exploit that\ncompany analysts believed was developed with AI.\n\"The threat actor planned to use the exploit in a wide-scale attack, but our proactive counter discovery may have prevented that from\nhappening,\" Google wrote. \nIn addition to sharing the findings from the threat actor with the larger security and AI community, Google used this incident to stay ahead of these threats,\nincluding enhancing product safeguards and protections, as well as testing different strategies to protect content. \n\"For Gemini, we mitigate model abuse through classifiers, in-model\nprotections and by disabling malicious accounts,\" Google explained. \"We leverage AI agents like Big Sleep, which detects software vulnerabilities, and use Gemini’s reasoning capabilities via the\nlikes of CodeMender to automatically fix them. Our efforts prove AI can also be a powerful tool for defenders.\"\nThis breach was not an isolated incident for the AI industry. Testing helps\nGoogle and others determine how to defend businesses. \nThe link between stopping malware or zero-day attacks and an AI model breaking out of a test environment can be attributed to giving\nthe model greater privilege than is needed.\nWhen an AI model is deployed to detect or stop sophisticated threats, it is often granted powerful tools and network access. If an attacker\nmanipulates that AI, those same defensive capabilities can be weaponized to break out of the sandbox and on to the internet where it can find an opening to break into another company's system.\nIt is unclear whether these companies -- from Google to OpenAI and Anthropic -- gave their AI model less privilege to enforce \"principle of least privilege\" access across its runtime, network and\ndata, treating the AI model as an non-trusted user executing non-trusted code.\nOpenAI experienced a similar scenario in July 2026 in a security incident with Hugging Face.\nIn this\ninstance, OpenAI did not stop the AI from accessing Hugging Face initially, and failed to enforce the Principle of Least Privilege. This allowed its unreleased research AI models to break out\nfrom the Sandbox and on to the internet, where they attacked Hugging Face on their own.","image_url":"https://s3.amazonaws.com/media.mediapost.com/dam/cropped/2024/03/18/googlegemini_ngr7TKf.jpg","lang":"en","published_at":"2026-09-20T18:40:51+00:00","fetched_at":"2026-09-20T19:15:05+00:00","status":"read","starred":0,"extract_state":"ok","summary_auto":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.","cluster_id":null,"extract_retries":0,"extract_error":null,"contract_version":"news_item.v1","format_contract_version":"news_item_formats.v1","dedup_url":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4861 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4861,"summary_length":370,"usable_text_length":4861,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4861,"summary_length":370}},"news_item":{"id":86552,"canonical_url":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","source_url":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","title":"Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026 - MediaPost","source_name":"MediaPost","author":null,"published_at":"2026-09-20T18:40:51+00:00","locale":"en","topic":"ai","tags":[],"rss_summary":"<a href=\"https://news.google.com/rss/articles/CBMiwAFBVV95cUxQVXVqSTJVWWxSaWhZN2tCUEZ0WGJ3N1VOMS1RWXNEOHJzOEhGUlhRaFVqSHItOS1nRXlEVG9CQ0FkRmlBdER1UXcweFFqTTJNVkNrOHZXa29JSUZRMGNtdmhQN2paa2tvWEZ2UWNzMDFzdERYbU91anBXbFVvRVBNWUw2MHMzUGNlUl9yZmhJazczWnVseXFIZVV5RE43QUF3WEJRU2pMVzRJcUE5VWlkbUJQSnRzT0o0WWVadW1jU0w?oc=5\" target=\"_blank\">Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026</a>&nbsp;&nbsp;<font color=\"#6f6f6f\">MediaPost</font>","full_text":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities.\nThe attack occurred in May as part of a test. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.\n\"Safe development of\npowerful AI models is critical and we invest deeply in this area,\" Heather Adkins, vice president, security engineering at Google, wrote in an email to MediaPost. \"In a standard evaluation,\nthe model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.\"\nIn one case the\nGemini model guessed passwords until it gained access to a protected system, The Wall Street Journal writes.\nadvertisement\nadvertisement\nIn two other cases, the model found credentials in a public\nrepository that allowed it to access protected systems.\nThe model autonomously stopped its intrusions the moment it logged in and realized it had breached actual corporate infrastructure\nrather than a simulation.\nGoogle said it did not consider the hacks warranted public disclosure, because its model did not cause harm and ended each intrusion immediately after determining its\nmistake.\nGoogle's security team \"has a long track record of reporting issues we find in other people's software and systems — even if it's as simple as a weak password,\" Adkins\nwrote. \n\"We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight\nthe importance of training powerful AI models to act responsibly.\"\n In one instance, the model hacked into the Israeli-based startup Irregular, which was founded by Dan Lahav, CEO and\nOmer Nevo, CTO.\nIrregular was also involved in a similar incident disclosed by OpenAI, Anthropic and Meta. \nWhen unreleased frontier models break containment, they reveal a\nmassive flaw in AI.\nIrregular disclosed the hacks to Google at the end of July after discovering that OpenAI hacked into Hugging Face, according to The Guardian. While Google\nconfirmed the hacks occurred, it did not feel at the time required to publicly disclose the incident because the models did not damage the companies. \nIronically, Google in May listed\na report on its Google Threat Intelligence Group\n(GTIG) blog detailing the latest observations from the cybersecurity group. The findings included the first time Google identified an attacker, or threat actor, using a zero-day exploit that\ncompany analysts believed was developed with AI.\n\"The threat actor planned to use the exploit in a wide-scale attack, but our proactive counter discovery may have prevented that from\nhappening,\" Google wrote. \nIn addition to sharing the findings from the threat actor with the larger security and AI community, Google used this incident to stay ahead of these threats,\nincluding enhancing product safeguards and protections, as well as testing different strategies to protect content. \n\"For Gemini, we mitigate model abuse through classifiers, in-model\nprotections and by disabling malicious accounts,\" Google explained. \"We leverage AI agents like Big Sleep, which detects software vulnerabilities, and use Gemini’s reasoning capabilities via the\nlikes of CodeMender to automatically fix them. Our efforts prove AI can also be a powerful tool for defenders.\"\nThis breach was not an isolated incident for the AI industry. Testing helps\nGoogle and others determine how to defend businesses. \nThe link between stopping malware or zero-day attacks and an AI model breaking out of a test environment can be attributed to giving\nthe model greater privilege than is needed.\nWhen an AI model is deployed to detect or stop sophisticated threats, it is often granted powerful tools and network access. If an attacker\nmanipulates that AI, those same defensive capabilities can be weaponized to break out of the sandbox and on to the internet where it can find an opening to break into another company's system.\nIt is unclear whether these companies -- from Google to OpenAI and Anthropic -- gave their AI model less privilege to enforce \"principle of least privilege\" access across its runtime, network and\ndata, treating the AI model as an non-trusted user executing non-trusted code.\nOpenAI experienced a similar scenario in July 2026 in a security incident with Hugging Face.\nIn this\ninstance, OpenAI did not stop the AI from accessing Hugging Face initially, and failed to enforce the Principle of Least Privilege. This allowed its unreleased research AI models to break out\nfrom the Sandbox and on to the internet, where they attacked Hugging Face on their own.","excerpt":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.","extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 4861 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html%3Fedition%3D143886","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4861 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4861,"summary_length":370,"usable_text_length":4861,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4861,"summary_length":370}}},"display_formats":["compact","card","full","digest_section","json"]},"daily_stack_record":{"title":"Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026 - MediaPost","url":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","summary":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.","source":"MediaPost","date":"2026-09-20T18:40:51+00:00","content":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities.\nThe attack occurred in May as part of a test. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.\n\"Safe development of\npowerful AI models is critical and we invest deeply in this area,\" Heather Adkins, vice president, security engineering at Google, wrote in an email to MediaPost. \"In a standard evaluation,\nthe model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.\"\nIn one case the\nGemini model guessed passwords until it gained access to a protected system, The Wall Street Journal writes.\nadvertisement\nadvertisement\nIn two other cases, the model found credentials in a public\nrepository that allowed it to access protected systems.\nThe model autonomously stopped its intrusions the moment it logged in and realized it had breached actual corporate infrastructure\nrather than a simulation.\nGoogle said it did not consider the hacks warranted public disclosure, because its model did not cause harm and ended each intrusion immediately after determining its\nmistake.\nGoogle's security team \"has a long track record of reporting issues we find in other people's software and systems — even if it's as simple as a weak password,\" Adkins\nwrote. \n\"We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight\nthe importance of training powerful AI models to act responsibly.\"\n In one instance, the model hacked into the Israeli-based startup Irregular, which was founded by Dan Lahav, CEO and\nOmer Nevo, CTO.\nIrregular was also involved in a similar incident disclosed by OpenAI, Anthropic and Meta. \nWhen unreleased frontier models break containment, they reveal a\nmassive flaw in AI.\nIrregular disclosed the hacks to Google at the end of July after discovering that OpenAI hacked into Hugging Face, according to The Guardian. While Google\nconfirmed the hacks occurred, it did not feel at the time required to publicly disclose the incident because the models did not damage the companies. \nIronically, Google in May listed\na report on its Google Threat Intelligence Group\n(GTIG) blog detailing the latest observations from the cybersecurity group. The findings included the first time Google identified an attacker, or threat actor, using a zero-day exploit that\ncompany analysts believed was developed with AI.\n\"The threat actor planned to use the exploit in a wide-scale attack, but our proactive counter discovery may have prevented that from\nhappening,\" Google wrote. \nIn addition to sharing the findings from the threat actor with the larger security and AI community, Google used this incident to stay ahead of these threats,\nincluding enhancing product safeguards and protections, as well as testing different strategies to protect content. \n\"For Gemini, we mitigate model abuse through classifiers, in-model\nprotections and by disabling malicious accounts,\" Google explained. \"We leverage AI agents like Big Sleep, which detects software vulnerabilities, and use Gemini’s reasoning capabilities via the\nlikes of CodeMender to automatically fix them. Our efforts prove AI can also be a powerful tool for defenders.\"\nThis breach was not an isolated incident for the AI industry. Testing helps\nGoogle and others determine how to defend businesses. \nThe link between stopping malware or zero-day attacks and an AI model breaking out of a test environment can be attributed to giving\nthe model greater privilege than is needed.\nWhen an AI model is deployed to detect or stop sophisticated threats, it is often granted powerful tools and network access. If an attacker\nmanipulates that AI, those same defensive capabilities can be weaponized to break out of the sandbox and on to the internet where it can find an opening to break into another company's system.\nIt is unclear whether these companies -- from Google to OpenAI and Anthropic -- gave their AI model less privilege to enforce \"principle of least privilege\" access across its runtime, network and\ndata, treating the AI model as an non-trusted user executing non-trusted code.\nOpenAI experienced a similar scenario in July 2026 in a security incident with Hugging Face.\nIn this\ninstance, OpenAI did not stop the AI from accessing Hugging Face initially, and failed to enforce the Principle of Least Privilege. This allowed its unreleased research AI models to break out\nfrom the Sandbox and on to the internet, where they attacked Hugging Face on their own.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html%3Fedition%3D143886","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 4861 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4861 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4861,"summary_length":370,"usable_text_length":4861,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4861,"summary_length":370}},"tags":[]},"fallback_formats":["markdown","json","html"],"actions":{"read":"/item/86552","export_markdown":"/api/items/86552/export?format=markdown","export_json":"/api/items/86552/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html%3Fedition%3D143886"},"formats":{"full":{"id":86552,"title":"Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026 - MediaPost","url":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","source":"MediaPost","author":null,"published_at":"2026-09-20T18:40:51+00:00","locale":"en","topic":"ai","tags":[],"excerpt":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.","full_text":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities.\nThe attack occurred in May as part of a test. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.\n\"Safe development of\npowerful AI models is critical and we invest deeply in this area,\" Heather Adkins, vice president, security engineering at Google, wrote in an email to MediaPost. \"In a standard evaluation,\nthe model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.\"\nIn one case the\nGemini model guessed passwords until it gained access to a protected system, The Wall Street Journal writes.\nadvertisement\nadvertisement\nIn two other cases, the model found credentials in a public\nrepository that allowed it to access protected systems.\nThe model autonomously stopped its intrusions the moment it logged in and realized it had breached actual corporate infrastructure\nrather than a simulation.\nGoogle said it did not consider the hacks warranted public disclosure, because its model did not cause harm and ended each intrusion immediately after determining its\nmistake.\nGoogle's security team \"has a long track record of reporting issues we find in other people's software and systems — even if it's as simple as a weak password,\" Adkins\nwrote. \n\"We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight\nthe importance of training powerful AI models to act responsibly.\"\n In one instance, the model hacked into the Israeli-based startup Irregular, which was founded by Dan Lahav, CEO and\nOmer Nevo, CTO.\nIrregular was also involved in a similar incident disclosed by OpenAI, Anthropic and Meta. \nWhen unreleased frontier models break containment, they reveal a\nmassive flaw in AI.\nIrregular disclosed the hacks to Google at the end of July after discovering that OpenAI hacked into Hugging Face, according to The Guardian. While Google\nconfirmed the hacks occurred, it did not feel at the time required to publicly disclose the incident because the models did not damage the companies. \nIronically, Google in May listed\na report on its Google Threat Intelligence Group\n(GTIG) blog detailing the latest observations from the cybersecurity group. The findings included the first time Google identified an attacker, or threat actor, using a zero-day exploit that\ncompany analysts believed was developed with AI.\n\"The threat actor planned to use the exploit in a wide-scale attack, but our proactive counter discovery may have prevented that from\nhappening,\" Google wrote. \nIn addition to sharing the findings from the threat actor with the larger security and AI community, Google used this incident to stay ahead of these threats,\nincluding enhancing product safeguards and protections, as well as testing different strategies to protect content. \n\"For Gemini, we mitigate model abuse through classifiers, in-model\nprotections and by disabling malicious accounts,\" Google explained. \"We leverage AI agents like Big Sleep, which detects software vulnerabilities, and use Gemini’s reasoning capabilities via the\nlikes of CodeMender to automatically fix them. Our efforts prove AI can also be a powerful tool for defenders.\"\nThis breach was not an isolated incident for the AI industry. Testing helps\nGoogle and others determine how to defend businesses. \nThe link between stopping malware or zero-day attacks and an AI model breaking out of a test environment can be attributed to giving\nthe model greater privilege than is needed.\nWhen an AI model is deployed to detect or stop sophisticated threats, it is often granted powerful tools and network access. If an attacker\nmanipulates that AI, those same defensive capabilities can be weaponized to break out of the sandbox and on to the internet where it can find an opening to break into another company's system.\nIt is unclear whether these companies -- from Google to OpenAI and Anthropic -- gave their AI model less privilege to enforce \"principle of least privilege\" access across its runtime, network and\ndata, treating the AI model as an non-trusted user executing non-trusted code.\nOpenAI experienced a similar scenario in July 2026 in a security incident with Hugging Face.\nIn this\ninstance, OpenAI did not stop the AI from accessing Hugging Face initially, and failed to enforce the Principle of Least Privilege. This allowed its unreleased research AI models to break out\nfrom the Sandbox and on to the internet, where they attacked Hugging Face on their own.","reading_time_min":4,"extraction":{"state":"ok","confidence":0.9,"error":null,"explanation":"High confidence: full text extraction produced 4861 characters.","diagnostics_url":"/api/diagnose?url=https%3A//www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html%3Fedition%3D143886","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4861 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4861,"summary_length":370,"usable_text_length":4861,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4861,"summary_length":370}}},"quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4861 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4861,"summary_length":370,"usable_text_length":4861,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4861,"summary_length":370}},"actions":{"read":"/item/86552","export_markdown":"/api/items/86552/export?format=markdown","export_json":"/api/items/86552/export?format=json","diagnose":"/api/diagnose?url=https%3A//www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html%3Fedition%3D143886"}},"digest":{"id":86552,"title":"Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026 - MediaPost","url":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","source":"MediaPost","topic":"ai","published_at":"2026-09-20T18:40:51+00:00","excerpt":"Google confirmed Friday that a Gemini AI model accessed the internet and hacked other companies' systems during a test of its cybersecurity capabilities. Gemini was given a fictional hacking task inside a sandbox environment, but a configuration flaw accidentally enabled live…","quality_bucket":"high","quality_reason":"High confidence: full text extraction produced 4861 characters.","reading_time_min":4,"cluster_id":null},"card":{"display_title":"Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026 - MediaPost","subtitle":"MediaPost · 2026-09-20","summary":"Google confirmed Friday that a Gemini AI model accessed the internet and hacked other companies' systems during a test of its cybersecurity capabilities. Gemini was given a fictional hacking task inside a sandbox…","badges":["quality:high"],"links":{"read":"/item/86552","original":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","diagnose":"/api/diagnose?url=https%3A//www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html%3Fedition%3D143886"},"quality_warning":null},"export":{"title":"Google: AI Model Hacked Companies In Cybersecurity Tests 09/21/2026 - MediaPost","url":"https://www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html?edition=143886","summary":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.","source":"MediaPost","date":"2026-09-20T18:40:51+00:00","content":"Google confirmed Friday that a Gemini AI model accessed the\ninternet and hacked other companies' systems during a test of its cybersecurity capabilities.\nThe attack occurred in May as part of a test. Gemini was given a fictional hacking task inside a\nsandbox environment, but a configuration flaw accidentally enabled live internet access, and the artificial intelligence (AI) model crossed into real-world networks.\n\"Safe development of\npowerful AI models is critical and we invest deeply in this area,\" Heather Adkins, vice president, security engineering at Google, wrote in an email to MediaPost. \"In a standard evaluation,\nthe model found public information online and guessed credentials to access websites it thought were part of the test. In all three of these instances, the model stopped.\"\nIn one case the\nGemini model guessed passwords until it gained access to a protected system, The Wall Street Journal writes.\nadvertisement\nadvertisement\nIn two other cases, the model found credentials in a public\nrepository that allowed it to access protected systems.\nThe model autonomously stopped its intrusions the moment it logged in and realized it had breached actual corporate infrastructure\nrather than a simulation.\nGoogle said it did not consider the hacks warranted public disclosure, because its model did not cause harm and ended each intrusion immediately after determining its\nmistake.\nGoogle's security team \"has a long track record of reporting issues we find in other people's software and systems — even if it's as simple as a weak password,\" Adkins\nwrote. \n\"We ensured the three entities were made aware, and we worked with our training partner on the changes they’ve now made to their testing processes. These events highlight\nthe importance of training powerful AI models to act responsibly.\"\n In one instance, the model hacked into the Israeli-based startup Irregular, which was founded by Dan Lahav, CEO and\nOmer Nevo, CTO.\nIrregular was also involved in a similar incident disclosed by OpenAI, Anthropic and Meta. \nWhen unreleased frontier models break containment, they reveal a\nmassive flaw in AI.\nIrregular disclosed the hacks to Google at the end of July after discovering that OpenAI hacked into Hugging Face, according to The Guardian. While Google\nconfirmed the hacks occurred, it did not feel at the time required to publicly disclose the incident because the models did not damage the companies. \nIronically, Google in May listed\na report on its Google Threat Intelligence Group\n(GTIG) blog detailing the latest observations from the cybersecurity group. The findings included the first time Google identified an attacker, or threat actor, using a zero-day exploit that\ncompany analysts believed was developed with AI.\n\"The threat actor planned to use the exploit in a wide-scale attack, but our proactive counter discovery may have prevented that from\nhappening,\" Google wrote. \nIn addition to sharing the findings from the threat actor with the larger security and AI community, Google used this incident to stay ahead of these threats,\nincluding enhancing product safeguards and protections, as well as testing different strategies to protect content. \n\"For Gemini, we mitigate model abuse through classifiers, in-model\nprotections and by disabling malicious accounts,\" Google explained. \"We leverage AI agents like Big Sleep, which detects software vulnerabilities, and use Gemini’s reasoning capabilities via the\nlikes of CodeMender to automatically fix them. Our efforts prove AI can also be a powerful tool for defenders.\"\nThis breach was not an isolated incident for the AI industry. Testing helps\nGoogle and others determine how to defend businesses. \nThe link between stopping malware or zero-day attacks and an AI model breaking out of a test environment can be attributed to giving\nthe model greater privilege than is needed.\nWhen an AI model is deployed to detect or stop sophisticated threats, it is often granted powerful tools and network access. If an attacker\nmanipulates that AI, those same defensive capabilities can be weaponized to break out of the sandbox and on to the internet where it can find an opening to break into another company's system.\nIt is unclear whether these companies -- from Google to OpenAI and Anthropic -- gave their AI model less privilege to enforce \"principle of least privilege\" access across its runtime, network and\ndata, treating the AI model as an non-trusted user executing non-trusted code.\nOpenAI experienced a similar scenario in July 2026 in a security incident with Hugging Face.\nIn this\ninstance, OpenAI did not stop the AI from accessing Hugging Face initially, and failed to enforce the Principle of Least Privilege. This allowed its unreleased research AI models to break out\nfrom the Sandbox and on to the internet, where they attacked Hugging Face on their own.","confidence":0.9,"diagnostics_url":"/api/diagnose?url=https%3A//www.mediapost.com/publications/article/418137/google-ai-model-hacked-companies-in-cybersecurity.html%3Fedition%3D143886","quality_bucket":"high","failure_kind":"none","retryable":false,"quality_reason":"High confidence: full text extraction produced 4861 characters.","quality_profile":{"profile_version":"extraction_quality.v2","bucket":"high","confidence":0.9,"failure_kind":"none","retryable":false,"retry_after_attempts":0,"reason":"High confidence: full text extraction produced 4861 characters.","operator_guidance":{"severity":"ok","recommended_action":"trust_full_text","next_step":"Use the extracted full text as the primary article source.","operator_label":"Ready","can_retry":false,"can_use_summary":false,"diagnostics_required":false},"content_depth":{"contract_version":"content_depth.v1","category":"full_text","label":"Full text","has_full_text":true,"has_summary":true,"content_length":4861,"summary_length":370,"usable_text_length":4861,"source_field":"content"},"legacy_collapsed":false,"signals":{"extract_state":"ok","extract_error":null,"extract_retries":0,"content_length":4861,"summary_length":370}},"tags":[],"format_contract_version":"news_item_formats.v1"}}}