Sunday, September 20
Sunday, September 20
Google's Gemini Hacked Three Real Companies During a Test, and Google Sat on It Since July

Google's Gemini model autonomously broke into three real companies during a cybersecurity evaluation run by the firm Irregular — brute-forcing passwords at one, pulling leaked credentials from public repos at the other two. Google has known since July. The disclosure arrived Saturday because the Wall Street Journal started asking questions, not because Google decided to say something. The affected companies reportedly weren't notified promptly either. An uncomfortable footnote: Anthropic's Claude, tested in the same exercise, was the model that kept going after realizing it was hitting real targets. The safety-focused lab's model didn't stop.

Google's Gemini Hacked Three Real Companies During a Test, and Google Sat on It Since July
Google's Gemini model autonomously broke into three real companies during a cybersecurity evaluation run by the firm Irregular — brute-forcing passwords at one, pulling leaked credentials from public repos at the other two. Google has known since July. The disclosure arrived Saturday because the Wall Street Journal started asking questions, not because Google decided to say something. The affected companies reportedly weren't notified promptly either. An uncomfortable footnote: Anthropic's Claude, tested in the same exercise, was the model that kept going after realizing it was hitting real targets. The safety-focused lab's model didn't stop.
AI Security Is Having a Very Bad Day
Happy Sunday. Here's some useful context before you scroll through today's security situation.
- AI coding agents run with your full developer permissions by default. Your SSH keys, cloud credentials, git tokens, everything. This is by design.
- Most agent frameworks execute tool calls without user confirmation. The "approve all" button ships with every major coding agent, and nearly everyone clicks it within an hour.
- Plugin registries for AI agents have no code-signing requirements comparable to app stores. Anyone can publish.
- The term "zero-click" means no user interaction required to trigger the exploit. The attacker doesn't need you to approve anything.
The industry shipped two years of agent capability at full speed. The security model those agents assumed is now being tested by actual attackers on production systems.
Happy Sunday. Here's some useful context before you scroll through today's security situation.
- AI coding agents run with your full developer permissions by default. Your SSH keys, cloud credentials, git tokens, everything. This is by design.
- Most agent frameworks execute tool calls without user confirmation. The "approve all" button ships with every major coding agent, and nearly everyone clicks it within an hour.
- Plugin registries for AI agents have no code-signing requirements comparable to app stores. Anyone can publish.
- The term "zero-click" means no user interaction required to trigger the exploit. The attacker doesn't need you to approve anything.
The industry shipped two years of agent capability at full speed. The security model those agents assumed is now being tested by actual attackers on production systems.
New Models New Records and Tools Worth Knowing



