← Back to blog Cybersecurity

Google's AI hacked three real companies on its own: what changes for patching and security in your Mexico operation

3 min read

On September 19, 2026, Mexican outlets picked up a Wall Street Journal report: Google confirmed that its Gemini AI found and exploited flaws at three real companies without a human telling it how.

These were authorized tests, not a loose attack. It still reaches your Mexico site, even if that site is twenty laptops, a firewall and a small server room.

What actually happened

Gemini took part in security exercises and, on its own, spotted vulnerabilities and used them to get in. No data theft, no ransom: the companies had signed off. Récord and Imagen Poblana reported it the same day.

What changes is speed. A person needs days to read an advisory and build the attack. An AI does not get tired and tries it against thousands of addresses at once.

From weeks to hours Patching when convenient no longer works: the gap between advisory and attack has closed.

It was not the only news that week

On September 20, researchers escaped the OpenAI Codex sandbox and ran commands on the host machine, as BleepingComputer reported. The sandbox is the isolated box where the AI is supposed to run without touching anything else.

A day earlier came the BragJack attacks, which hijack AI browser agents through malicious extensions. In plain terms: the extension someone in purchasing installed to summarize pages can give orders to an assistant that already has your email session open.

The three fronts that get scanned first

An automated attacker does not start with your accounting system. It starts with whatever is published to the internet, because that is what it sees from outside without asking.

FrontWhat it looks forWhat to check today
Firewall and VPNUnpatched vendor versionModel, version and firmware date
RDP and remote desktopsOpen port, no second factorNobody reaching RDP directly
Cameras and PBXFactory password, old firmwareNVR and phone system off the internet

In our experience the most common finding is not an exotic flaw. It is a CCTV recorder someone published back in 2021 to watch from a phone, and nobody touched again. More on that in exposed IP cameras.

Inventory first, then patches

Four columns are enough What it is, where it is, what version it runs, whether it is visible from the internet.

You cannot patch what you do not know you have. And there is always something nobody remembers: the server at the branch that closed, the PC wired to the scale, the one at reception that never shuts down.

When headquarters sits in another country, an unknown device in Mexico stays unknown longer. Ask for that list in writing, with a review date, as part of the service.

A patch window you can actually keep

Fixed window, not heroics Critical in 72 hours. The rest, one Saturday a month, scheduled in Mexico local time.

And yes, patches sometimes break things. This year we saw updates that knocked out Remote Desktop and others that broke copy and paste in Excel.

So order matters: a test machine, then a pilot group of three or four people who speak up fast, then everyone else. With a verified backup before you start, never after.

What not to hand an AI agent

Three simple rules No admin rights, no deleting or paying alone, and browser extensions from an approved list only.

Most teams already use AI assistants whether or not anyone approved it. Give an agent its own account, minimum permissions and a log of what it did.

No deleting, paying or sending external email without a person approving first.

Reviewing the internet-facing surface of a Mexico site
Want us to check what your Mexico site publishes to the internet? Foto: Pexels

What about your operation?

If nobody can say from memory which devices at your Mexico site are visible from the internet, or when the firewall was last patched, that is where to start.

At ProcessBi the plan with a written SLA covers inventory, a monthly patch window, monitoring of internet-facing assets and hardening of Hikvision CCTV, firewall and remote access.

Request your exposed surface review — we reply the same business day.

Your path

Running IT in Mexico from abroad

32 of 32
  1. Smart hands ✓ Read You are here 2 min
  2. Remote support ✓ Read You are here 3 min
  3. Nearshoring checklist ✓ Read You are here 2 min
  4. Retail rollouts ✓ Read You are here 2 min
  5. Fake IT support ✓ Read You are here 3 min
  6. Backups that restore ✓ Read You are here 3 min
  7. Secure M365 ✓ Read You are here 3 min
  8. Windows 10 deadline ✓ Read You are here 4 min
  9. Audit app access ✓ Read You are here 3 min
  10. CEO fraud ✓ Read You are here 4 min
  11. Office 2016 cutoff ✓ Read You are here 3 min
  12. Patch today ✓ Read You are here 4 min
  13. Patch VMware ✓ Read You are here 4 min
  14. Office 2021 EOL ✓ Read You are here 3 min
  15. Starlink for sites ✓ Read You are here 3 min
  16. Cardless access ✓ Read You are here 4 min
  17. Control AI on PCs ✓ Read You are here 4 min
  18. ScreenConnect flaw ✓ Read You are here 4 min
  19. Server 2022 EOL ✓ Read You are here 3 min
  20. Exposed cameras ✓ Read You are here 3 min
  21. Domain trust fix ✓ Read You are here 4 min
  22. Patch Cisco ISE ✓ Read You are here 3 min
  23. Protect the plant ✓ Read You are here 3 min
  24. Move to 25H2 ✓ Read You are here 4 min
  25. Outages and UPS ✓ Read You are here 3 min
  26. IT maintenance ✓ Read You are here 4 min
  27. Third-party scripts ✓ Read You are here 3 min
  28. License audit ✓ Read You are here 4 min
  29. Bajío fiber corridor ✓ Read You are here 3 min
  30. Check Point flaw ✓ Read You are here 4 min
  31. Cashless payments ✓ Read You are here 3 min
  32. AI that hacks alone ✓ Read You are here 3 min
  33. Field services
Next See IT field services in Mexico