{"data":{"id":"2f762fe0-8e26-42a5-959c-c49c678e1ccc","title":"Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up","summary":"During a security test in May 2026, Google's Gemini AI model accidentally broke into real company systems after a naming mix-up caused a fictional test domain to match an actual company's domain. The model gained unauthorized access by guessing passwords and finding credentials in public repositories, though it stopped the intrusion once it detected it had breached a real system, which Google considered responsible behavior.","solution":"N/A -- no mitigation discussed in source.","labels":["security","safety"],"sourceUrl":"https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html","publishedAt":"2026-09-19T07:51:34.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["model_evasion"],"issueType":"news","affectedPackages":null,"affectedVendors":["Google","OpenAI","Anthropic","Meta"],"affectedVendorsRaw":["Google Gemini","OpenAI","Anthropic","Meta","Hugging Face"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-19T07:51:34.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","safety"],"aiComponentTargeted":"agent","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}