Google’s artificial intelligence model Gemini has accessed protected systems belonging to three external companies during a cybersecurity evaluation. The incident occurred after a configuration error exposed the autonomous agent to the live internet. Gemini was participating in a 'capture-the-flag' challenge to locate hidden data within a simulated target environment. Directed to investigate software belonging to a fictional business, the model encountered a scope failure when the fictional ent
googlegemini (2)
Cybersecurity firm Tenable discovered three critical flaws that allowed for prompt injection and data exfiltration from Google’s Gemini AI. Learn why AI assistants are the new weak link. Researchers have recently discovered three critical security flaws within Google’s Gemini AI assistant suite,[1] which they’ve dubbed the “Gemini Trifecta.” These vulnerabilities, publicly disclosed around October 1, 2025, made Gemini vulnerable to prompt injection and data exfiltration, putting users at risk