#AxisOfEasy 469: Google Confirms Gemini Broke Into Three Real Companies During A Security Test

 


Weekly Axis Of Easy #469


Last Week’s Quote was: “How do you beat Bobby Fischer? You play him at any game but chess.” — was by Warren Buffett. Les got it right first. Congratulations.

This Week’s Quote: “Wonder is the feeling of the philosopher, and philosophy begins in wonder.” By ???

THE RULES: No searching up the answer, must be posted at the bottom of this blog post, in the comments section.
The Prize: First person to post the correct answer gets their next domain or hosting renewal on us.


This is your easyDNS #AxisOfEasy Briefing for the week of September 21st, 2026. Our Technology Correspondent Joann L Barnes and easyCEO Mark E. Jeftovic send out a short briefing on the state of the ‘net and how it affects your business, security and privacy.

To Listen/watch this podcast edition with commentary and insight from Joey and Len the Legend click here.

In this issue:

  • Google Confirms Gemini Broke Into Three Real Companies During A Security Test
  • Cisco Patches Two Actively Exploited Zero-Days In Two Days
  • Microsoft Takes Down An AI-Powered Phishing Platform That Hit 12,000 Accounts
  • Ireland Fines Google $463 Million Over How It Handled Your Location History
  • A Maximum-Severity D-Link Router Bug Has No Patch And A Public Exploit

Elsewhere Online:

  • CISA Orders Feds To Patch A Zyxel Switch Flaw Being Exploited For Data Theft
  • FBI Seizes NightmareStresser, One Of The Longest-Running DDoS-For-Hire Services
  • A Malicious npm Package Posed As A Twilio Security Tool To Steal Developer Credentials
  • CISA Flags Three Actively Exploited Linux Kernel Flaws, Gives Feds 72 Hours
  • Meta’s Muse AI Assistant Had A Zero-Day That Could Turn It Into A Mac Backdoor

easyHermes Is Here

We’re pleased to announce the expansion of our agentic hosting platform with the rollout of easyHermes, the latest agent-enabled VPS appliance on the easyNode.ai platform. It’s a Nous Hermes–powered conversational agent that sits on the same private VPS and control panel as easyClaw, but is built for natural, steerable conversation — assistants, knowledge bases, and chat workflows — rather than shell access and autonomous ops.

Now you can finally settle the “openClaw vs. Hermes” argument for yourself, or just run both and let them fight it out.

Check it out today, and get your first month on us when you use promo code:

AXISOFEASY ⇒ https://easynode.ai


Google Confirms Gemini Broke Into Three Real Companies During A Security Test

Google confirmed on September 18 that its Gemini model accessed the protected systems of three real companies during a cybersecurity evaluation in May, run by Israeli AI-testing firm Irregular as a capture-the-flag exercise. A bug in the test environment left outbound internet access open when it shouldn’t have been. In one case, Gemini repeatedly guessed a password until it got into a protected system; in the other two, it found valid credentials sitting in public code repositories and used them. In each case, the model recognized it had reached a real company rather than its intended simulated target, and stopped on its own.

Google says the affected companies were notified, no harm was done, and Irregular has since added safeguards to prevent unintended internet access during evaluations. The interesting part isn’t that a model “hacked” anyone — it’s that ordinary opsec failures, leaked credentials in a public repo, a guessable password, were sufficient for an AI agent with plain internet access to reach production systems entirely by accident, with no attacker directing it anywhere. If your organization’s credentials or API keys are sitting in a public repository right now, assume something will eventually find and use them, model or human. That’s worth auditing today, not on next quarter’s compliance calendar.

More via The Record

Cisco Patches Two Actively Exploited Zero-Days In Two Days

Cisco disclosed and patched CVE-2026-76461 (CVSS 9.8) in Secure Email Gateway on September 15 — an unauthenticated SQL injection triggered by simply sending a crafted email, giving an attacker root command execution — then followed it two days later with CVE-2026-76460 (CVSS 10.0), an authentication bypass in Identity Services Engine that also yields root. Both were already under active exploitation before Cisco shipped fixes. CISA added both to its Known Exploited Vulnerabilities catalog and gave federal agencies a three-day window to patch the ISE bug, one of the tightest deadlines it’s issued all year.

Cisco says the two bugs are unrelated — different products, different vulnerability classes — and that the consecutive CVE numbers reflect first-come-first-served assignment, not any real connection. Coincidence or not, root access on either an email gateway or an identity and access control platform is a serious foothold, and the ISE bug in particular can also let an attacker erase the log data an incident responder would use to notice they were ever there. If you run either product, patch now and check Cisco’s published indicators of compromise regardless of whether you believe you were hit.

More via CyberScoop

Microsoft Takes Down An AI-Powered Phishing Platform That Hit 12,000 Accounts

Microsoft, working with Cloudflare, Coinbase, OpenAI, and several threat-intel firms, seized the infrastructure behind EvilTokens this week — a subscription phishing-as-a-service platform ($1,500 signup, $500 a month) that used AI at every stage of the attack: picking targets, writing the social-engineering messages, and later sifting through compromised inboxes for anything worth stealing. The platform specialized in device-code phishing, abusing the login flow built for devices like smart TVs that can’t run a normal browser, and compromised more than 12,000 accounts across 10,000-plus organizations since February. London’s Metropolitan Police arrested two men, aged 32 and 38, on September 11.

The AI part here isn’t the exotic headline — it’s the mundane one. EvilTokens didn’t need a novel exploit; it needed customized phishing copy at scale and a way to triage what it stole, and generative text models are cheap and good enough now to handle both. That’s the shape of AI-assisted crime actually showing up in the wild: not autonomous hacking, but better-written fraud run as a commercial service with subscription pricing and customer support. If your organization allows device-code sign-in flows, that’s worth a second look — it’s a legitimate feature built for hardware that can’t display a normal login page, and precisely because of that, it’s a blind spot most phishing training never covers.

More via The Hacker News

Ireland Fines Google $463 Million Over How It Handled Your Location History

Ireland’s Data Protection Commission fined Google €403 million ($463 million) on September 21, closing a six-year investigation into how the company processed location data between 2018 and early 2020 through Web & App Activity, Location History, and Android’s Location Accuracy feature. The DPC found Google failed to process that data lawfully and fairly, and separately failed to meet GDPR’s transparency requirements across all three features. Google has six months to bring its practices into compliance, and says the case “centers around historical policies that have since been updated.”

It’s the DPC’s fourth-largest GDPR fine to date, behind three of its own prior actions against Meta and TikTok, and a reminder that “we fixed it years ago” doesn’t make the earlier years go away — regulators are still working through 2018-2020 practices in 2026, on a category of data that’s only gotten more precise and more valuable since. The DPC also noted it has three more open investigations into Google running in parallel. If your organization is still sitting on old opt-in flows or retention practices you “meant to update eventually,” this is a useful data point on how long that debt can sit on the books before it comes due.

More via Help Net Security

A Maximum-Severity D-Link Router Bug Has No Patch And A Public Exploit

D-Link warned customers on September 18 of a CVSS 10.0 vulnerability in its legacy DIR-822A routers — a stack-based buffer overflow in the DHCP server component, triggered by a crafted DHCP packet, that needs no authentication and no user interaction to exploit. A public proof-of-concept is already circulating. A second, related bug in the router’s L2TP parser (CVSS 9.9) requires only low-level privileges and is also unpatched. Neither has been confirmed exploited in the wild yet, but D-Link devices are a perennial botnet target — CISA currently tracks 26 separate D-Link flaws with confirmed real-world exploitation.

“No patch yet, but a public proof-of-concept exists” is exactly the window that turns a disclosed bug into a live campaign, and D-Link’s own advice underlines how exposed this class of device usually is: keep the router’s management interface off the internet and restrict remote access. If you or a client is still running a DIR-822A, that’s worth checking today regardless of firmware version — the vulnerable component doesn’t require an intentionally exposed management panel, just another device on the same local network sending it a bad packet.

More via BleepingComputer


Also on AxisOfEasy this week:
Nothing new in Curated Posts since our last check — still nothing since May. We’re not going to pad this section with filler just to fill space; when something worth your time crosses our desk, it’ll be here.


Elsewhere Online:

CISA Orders Feds To Patch A Zyxel Switch Flaw Being Exploited For Data Theft
Read: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/

FBI Seizes NightmareStresser, One Of The Longest-Running DDoS-For-Hire Services
Read: https://www.securityweek.com/nightmarestresser-ddos-service-disrupted-in-international-operation/

A Malicious npm Package Posed As A Twilio Security Tool To Steal Developer Credentials
Read: https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html

CISA Flags Three Actively Exploited Linux Kernel Flaws, Gives Feds 72 Hours
Read: https://www.techtimes.com/articles/327741/20260919/cisa-flags-three-actively-exploited-linux-kernel-flaws-orders-federal-patch-sunday.htm

Meta’s Muse AI Assistant Had A Zero-Day That Could Turn It Into A Mac Backdoor
Read: https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html


Previously on #AxisOfEasy

If you missed the previous issues, they can be read online here:

 

Leave a Reply

Your email address will not be published. Required fields are marked *