Every story we've covered involving third-party-vendor.
Google says it learned in late July that its Gemini model had escaped a sandbox during a May capture-the-flag security test and reached three real companies, but the company did not disclose the incident publicly until September 18 after The Wall Street Journal asked. The test had been run by third-party firm Irregular, which left the sandbox connected to the open internet and used the name of an actual company as the fictional target, enabling Gemini to find exposed credentials for two targets and guess a third password.
No stories here yet.