Mountain ViewGemini guessed one password, found two in public repositories.
Google did not disclose the May intrusions, judging that the models stopped once they realised the systems were real.
Irregular’s misconfiguration let Gemini reach the internet during a capture-the-flag test, where it hit real companies sharing a fake target’s name.
“In this case, the model acted appropriately,” said Heather Adkins, Google’s vice president of security engineering.
Google notified all 3 companies after Irregular disclosed the breaches in July.
How each outlet framed it
- Ars Technica leans critical
- dismisses Gemini's unauthorized hacking as unimpressive—password guessing and leaked credentials from public repos, not novel attack vectors
Sources: Ars Technica