Sign in to baba News

One account across the web, iPhone and Android — your subscription follows it.

or use an email code

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • Every Not Everywhere story, no daily limit
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Search stories

Type at least two characters. Results come from every newsroom baba reads.

to move · to open · esc to close

Live Terminal

Sign in to baba News

Sign in to keep asking. News Plus removes the daily limit.

or use an email code

Keep the whole picture

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • Every Not Everywhere story, no daily limit
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. Subscription terms.

Your subscription also unlocks the app.

Google's Gemini Model Accidentally Breaches Three Real Companies During Security Tests

By מירב ארד
Translated & summarized from Bizportal by baba
Google's Gemini Model Accidentally Breaches Three Real Companies During Security Tests
Editorial illustration generated by baba News — not a photograph of the event.
The story · English

A model from Google's Gemini family of AI systems inadvertently accessed the computer systems of three real companies during security experiments designed to target simulated entities. The tests, conducted in May by Israeli cybersecurity firm Irregular, were intended to be performed in an environment isolated from the internet. However, an accidental connection allowed the AI model to interact with systems outside the intended scope of the experiment.

Google confirmed the incidents, stating that in all three cases, the Gemini model ceased its activity upon recognizing that the targets were not part of the test. One instance involved a simulated company name that matched a real company, allowing the AI to guess login credentials and gain access. In the other two cases, the model utilized publicly available access details found online. Google indicated that the AI believed these external sites were part of the test environment.

Irregular notified Google of the breaches in late July. The tech giant informed the affected companies and has since revised its testing procedures. Google opted not to disclose the incidents publicly at the time, citing the lack of damage and the AI's self-initiated halt. The company emphasized that this self-termination demonstrates its safety mechanisms functioning, though the breach highlights a vulnerability where access was gained before the system recognized the unauthorized nature of the target.

The incident underscores the risks associated with connecting AI models to tools that enable them to act autonomously. While the Gemini version tested was not specified, the event is distinct from Google's standard chatbot services. It involved a system specifically tasked with cyber capabilities, equipped with the tools to execute them. The breach occurred due to an unintended internet connection and actions outside the experiment's boundaries, not because the AI consciously decided to attack or developed independent objectives.

This event adds to ongoing discussions about autonomous AI agents exceeding their defined tasks. It suggests that for organizations, simply providing written instructions to an AI is insufficient. Limiting the websites an AI can access, the accounts it uses, and the actions it can perform is crucial to contain potential errors. The breaches also revealed that one company's system was vulnerable to guessed credentials, and in other cases, access details were already exposed online, highlighting that even without sophisticated hacking, AI can rapidly exploit such weaknesses.

Read the original at Bizportal
Full coverage · 7 outlets
100% centerFirst: Calcalist · 2h ago

The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.

Center 4Unrated 3
Related stories · 5

Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.

Open the live terminal