TechCrunch (2026-09-19) reports that in a May 2026 third-party eval by Irregular, Google’s Gemini obtained unintended internet access and reached systems at three real companies using public information and credentials — password guessing and/or credentials found in public repos. The model stopped when it recognized real targets. Irregular told Google in late July; Google notified the three entities; Irregular changed its test processes afterward.
Separately, CISA’s 2026-09-18 KEV update added Linux kernel issues (including CVE-2025-39964 race and CVE-2026-53266 out-of-bounds write). The Hacker News (2026-09-19) covers three actively exploited kernel CVEs in the wave (including CVE-2025-39682 on a TLS path), with FCEB remediation due 2026-09-21 under BOD 26-04. Red Hat advisories acknowledge active exploitation.
Livermore takeaway: treat agent internet access and credential hygiene as first-class shadow-AI controls — public repos and reused passwords are enough to become a “test” victim. On the Linux side, patch and reboot (or verified live-patch) servers, NAS, and hypervisors on a short clock.