Gemini Exits Testing and Accesses Three Real-World Company Systems

Two separate security incidents have raised concerns about the risks of giving advanced AI systems access to tools, computers, and online services.

Google said Gemini AI agents accessed systems belonging to three outside companies during a security test. Separately, researchers at Hacktron AI said they used Anthropic’s Claude to help exploit vulnerabilities that gave them access to multiple OpenAI employees’ ChatGPT accounts.

Researchers Used Claude to Access OpenAI Accounts

Hacktron AI researchers said they combined two serious security vulnerabilities on July 25, 2026, allowing them to access several OpenAI employee ChatGPT accounts.

The researchers said these accounts could potentially provide access to OpenAI’s internal code repositories and connected services such as GitHub, Slack, email, and Codex.

To show the level of access without viewing sensitive information, they used an employee’s Codex account to create a pull request in OpenAI’s internal code repository.

Vulnerability Linked to Discourse and Debian

The attack involved Discourse, the software used for OpenAI’s community forum.

Hacktron AI said the Discourse Docker image was based on Debian 12 and contained an outdated dependency called libheif.

ALSO READ  Government Gets More Than 70 Lakh Applications for Just 1,200 Jobs Posted on Main Portal

The researchers warned organizations running Discourse themselves to rebuild their installations, because vulnerable versions could potentially allow code execution through an uploaded image.

Gemini Reached Three Real Company Systems

In a separate incident, Google said Gemini AI agents accessed systems belonging to three outside organizations during a cybersecurity challenge organized by Israeli security company Irregular.

The Gemini agents were expected to stay inside an isolated testing environment. However, a bug in the test infrastructure accidentally gave them access to the wider internet.

Gemini then mistakenly interacted with real company systems, believing they were part of the security exercise.

The agents stopped after recognizing that they had reached real company infrastructure. Google said it found no evidence of damage from the incidents.

Google Says It Was Not AI Misalignment

Google said it does not consider the Gemini incident to be AI misalignment.

Instead, the company described it as a case of mistaken identity, where the AI believed the external systems were part of the authorized security te

Leave a Reply

Your email address will not be published. Required fields are marked *