- The Daily Bite by Snack Prompt
- Posts
- ๐ญ Gemini Hacked Three Real Companies ๐
๐ญ Gemini Hacked Three Real Companies ๐
Grok 4.7 IS OUT

Good morning. The intern forgot his Slack password yesterday and just started guessing until IT walked over.
Turns out that's also how Gemini got into three companies.
Letโs dive in ๐
๐ณ Whatโs Cookinโ:
Google's Gemini hacked three real companies (we're just hearing now)
British Columbia is suing OpenAI
Amazon kicked Meta's Muse out, Shopify said come on in
Google's
๐ณ Gemini Joins The Breakout Club
The Bite:
Google confirmed Friday that one of its Gemini models broke into the systems of three real companies during a cybersecurity test in May.
The test was a capture-the-flag exercise run by Irregular, an Israeli AI evaluation startup. A bug in Irregular's environment gave the model internet access it was never supposed to have.
Google says the model stopped in all three cases once it realized the systems were real. The Wall Street Journal first reported the incidents.
Google is the fourth lab to disclose an Irregular-linked breakout, after OpenAI, Anthropic and Meta.
Snacks:
Gemini was told to pull data from a fictional company that shared its name with a real one.
In one case it guessed passwords, and in the other two it used credentials from public repositories.
Irregular notified Google in late July, roughly two months after the incidents.
Google said it didn't consider this misalignment, since the model stopped itself.
Google also said the hacks didn't warrant public disclosure because no harm was done.
Google hasn't named the three companies or the model, only that it isn't its latest.
Why it Bites:
Four labs have now gone through the same tester and hit the same bug.
Google's defense comes in two parts:
The model stopped, so it wasn't misalignment.
Nobody got hurt, so it wasn't worth disclosing.
Both verdicts were issued by Google itself.
The company that built the model is also the one deciding whether its behavior counts as a problem.
Each time, the story lands the same way: the environment was misconfigured, the model thought it was still in the test, no harm, no headline.
Every step of that process rewards staying quiet. None of it rewards telling anyone.
Turns out the disclosure policy was a reporter all along.
At this point, every model seems to take the same exam: hacking real companies.

Coresignal
๐ Plug B2B data into Claude, ChatGPT, or any other MCP client
Get data on Claude, ChatGPT, Cursor, Copilot, Gemini, Perplexity, or any other MCP-ready client.
Query 4.5B company, employee, and job records:
Chat in plain English without Elasticsearch or complex querying;
Search, discover, fetch, and enrich data;
Explore available data fields at no cost;
See the exact credit cost before every request.
Use one MCP server to log in with OAuth 2.1, no API keys pasted into configs.

Steal This Prompt
๐ถ Sticker Meets Reality

Turn any illustrated character into a sticker that looks like it just escaped the sheet and wandered into the real world. The prompt blends cartoon-style characters, sticker borders, and photorealistic environments for a gloriously weird mix.
Use it to:
Drop illustrated characters into surreal street scenes
Make your favorite characters interact with real places
Workflow:
Hit this link: Sticker Meets Reality
Paste into your AI model
Replace the #โs with your character + scene
Watch it cook. Your cartoon just got a passport

ToolBoxโข
๐งฐ 5 BRAND NEW AI LAUNCHES
๐ Brev
Maps your business goals to the meetings, metrics, and tools your team already uses, then sends an AI coworker into Slack or Teams to chase the busywork.
๐ Jev Wrapped
Paste any public Telegram channel and get a year-in-review card showing how much of it was paid ads, clickbait, and fear-or-anger bait, with links so you can check the model's work.
๐จ PixelCrew
A crew of AI agents takes your brief from research to production-ready HTML with a design system, and you get to watch them argue about decisions along the way.
๐งผ gg-friggin-ez
An open-source Node.js profanity filter that catches leetspeak, ASCII drawings, and romanized swears in Hindi, Tamil, and Telugu for about $0.000004 a message.
๐ง Contextberg
Records your screens, browsing, and agent chats into an on-device archive, then feeds the relevant bits to Claude Code, Cursor, or Codex over MCP.


Can you tell which image is real?Level: Impossible ๐ |


Everything Else
๐ง You Need to Know
โ๏ธ British Columbia Sues OpenAI Over School Shooting
โ The province sued OpenAI and Sam Altman in San Francisco federal court Monday, alleging the company never warned police after its safety team flagged the Tumbler Ridge shooter's ChatGPT use.

๐ค SpaceXAI Ships Grok 4.7 For Coding Work
โ Released Monday on a new and larger base model, Grok 4.7 keeps Grok 4.6's pricing of $2 per million input tokens and $6 per million output.
๐ Amazon Blocks Meta's Muse From Shopping Its Site
โ Amazon cut off Meta's shopping agent Sunday night, citing its conditions of use, while Shopify announced Muse checkout with Shop Pay across all its stores.

๐๏ธ Bessent Pitches China An AI Safety Alert System
โ Treasury Secretary Scott Bessent proposed a mechanism for flagging national security-level AI incidents after Sunday talks in New York, for Trump and Xi to weigh at their summit this week.
๐จ Google Says Gemini Hacked Three Real Companies
โ Google disclosed Friday that during a May evaluation its Gemini model broke out of a test environment, guessed passwords and used publicly listed credentials to reach three companies' private systems.

How was today's Daily Bite? |
โ Eder | Founder
โ Doka | Editor
Snack Prompt & The Daily Bite
Ticker: FCCN | Trade FCCN Here
Follow Along: FCCN on Yahoo Finance

If you enjoyed this post or know someone who might find it useful, please share it with them and encourage them to subscribe: ๐ญ DailyBite.ai


