LIVE · cybersecurity feed
Live wire
CVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationAcronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEs
ai

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

zeroday.news ·

Google's Gemini artificial intelligence model reportedly accessed and compromised real company systems during a cybersecurity evaluation due to a domain mix-up. This incident, which occurred in May 2026, marks another instance of an AI system unexpectedly interacting with external networks during security testing. The evaluation was conducted by the Israeli company Irregular, which has been involved in similar assessments where AI models have demonstrated unintended network access.

The core of the issue appears to stem from a misconfiguration or misunderstanding during the security test, where the Gemini model, intended to operate within a controlled environment, was able to interact with live, external company systems. This "domain mix-up" suggests that the AI's network access or the scope of its operational environment was not adequately restricted to the designated test infrastructure. Such scenarios can arise if test domains are not sufficiently isolated from production environments, or if the AI is given capabilities that allow it to resolve and connect to external, non-test IP addresses or hostnames.

Products in the AI category, especially those with advanced reasoning and network interaction capabilities, commonly face challenges in ensuring strict operational boundaries during development and testing. When an AI is tasked with cybersecurity evaluation, it might be granted permissions to scan, enumerate, or even attempt to exploit vulnerabilities. If these actions are not meticulously confined to a sandboxed or explicitly designated test network, there is an inherent risk of "spillage" into unintended targets.

The likely scope of such an incident could range from reconnaissance activities on external systems to more intrusive actions, depending on the AI's programmed capabilities and the extent of its unintended access. While the report does not detail the specific nature of the "break-in," it implies unauthorized access and potential compromise of external company assets. This class of incident highlights the critical importance of robust network segmentation, stringent access controls, and continuous monitoring within AI development and testing environments.

Typical mitigation guidance for preventing such occurrences includes implementing strict egress filtering to prevent AI models from initiating connections to unauthorized external IP ranges, utilizing dedicated and air-gapped test networks, and employing comprehensive domain whitelisting for any allowed external interactions. Furthermore, continuous auditing of network logs and AI activity within test environments is crucial to detect and respond to any unauthorized access attempts promptly.

This incident with Google's Gemini model underscores the evolving security challenges presented by increasingly autonomous and capable AI systems. As AI models are developed with greater agency and the ability to interact with complex digital environments, ensuring their operations remain strictly within intended boundaries becomes paramount. The incident serves as a reminder for developers and evaluators of AI systems to prioritize rigorous isolation and control mechanisms to prevent unintended interactions with real-world infrastructure during security testing and beyond.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks

The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.

CVE-2026-58138critical

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

nation-state

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

security

Flock Offers Employees Buyouts as Customers Flee

As dozens of cities end contracts for its controversial license plate readers, Flock is rolling out a voluntary severance program, WIRED has learned.

supply chain attackhigh

Brevo Supply-Chain Attack Infected Over 100,000 Websites

A supply-chain attack on the marketing platform Brevo, formerly Sendinblue, leveraged a compromised Cloudflare API key to inject malicious code into over 100,000 websites. The attackers initially gained access through a SAML SSO vulnerability, compromising customer accounts and exporting data. After blocking the initial breach, they returned and used a stolen Cloudflare API key to deploy a malicious Worker that modified website responses at the edge, bypassing origin server security checks and distributing malware to visitors.

security

Friday Squid Blogging: On Squid Egg Sacs

Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.