Google's AI hacked three real companies on its own: what changes for patching and security in your Mexico operation
On September 19, 2026, Mexican outlets picked up a Wall Street Journal report: Google confirmed that its Gemini AI found and exploited flaws at three real companies without a human telling it how.
These were authorized tests, not a loose attack. It still reaches your Mexico site, even if that site is twenty laptops, a firewall and a small server room.
What actually happened
Gemini took part in security exercises and, on its own, spotted vulnerabilities and used them to get in. No data theft, no ransom: the companies had signed off. Récord and Imagen Poblana reported it the same day.
What changes is speed. A person needs days to read an advisory and build the attack. An AI does not get tired and tries it against thousands of addresses at once.
It was not the only news that week
On September 20, researchers escaped the OpenAI Codex sandbox and ran commands on the host machine, as BleepingComputer reported. The sandbox is the isolated box where the AI is supposed to run without touching anything else.
A day earlier came the BragJack attacks, which hijack AI browser agents through malicious extensions. In plain terms: the extension someone in purchasing installed to summarize pages can give orders to an assistant that already has your email session open.
The three fronts that get scanned first
An automated attacker does not start with your accounting system. It starts with whatever is published to the internet, because that is what it sees from outside without asking.
| Front | What it looks for | What to check today |
|---|---|---|
| Firewall and VPN | Unpatched vendor version | Model, version and firmware date |
| RDP and remote desktops | Open port, no second factor | Nobody reaching RDP directly |
| Cameras and PBX | Factory password, old firmware | NVR and phone system off the internet |
In our experience the most common finding is not an exotic flaw. It is a CCTV recorder someone published back in 2021 to watch from a phone, and nobody touched again. More on that in exposed IP cameras.
Inventory first, then patches
You cannot patch what you do not know you have. And there is always something nobody remembers: the server at the branch that closed, the PC wired to the scale, the one at reception that never shuts down.
When headquarters sits in another country, an unknown device in Mexico stays unknown longer. Ask for that list in writing, with a review date, as part of the service.
A patch window you can actually keep
And yes, patches sometimes break things. This year we saw updates that knocked out Remote Desktop and others that broke copy and paste in Excel.
So order matters: a test machine, then a pilot group of three or four people who speak up fast, then everyone else. With a verified backup before you start, never after.
What not to hand an AI agent
Most teams already use AI assistants whether or not anyone approved it. Give an agent its own account, minimum permissions and a log of what it did.
No deleting, paying or sending external email without a person approving first.
What about your operation?
If nobody can say from memory which devices at your Mexico site are visible from the internet, or when the firewall was last patched, that is where to start.
At ProcessBi the plan with a written SLA covers inventory, a monthly patch window, monitoring of internet-facing assets and hardening of Hikvision CCTV, firewall and remote access.
Request your exposed surface review — we reply the same business day.
Your path
Running IT in Mexico from abroad
32 of 32- Smart hands ✓ Read You are here 2 min
- Remote support ✓ Read You are here 3 min
- Nearshoring checklist ✓ Read You are here 2 min
- Retail rollouts ✓ Read You are here 2 min
- Fake IT support ✓ Read You are here 3 min
- Backups that restore ✓ Read You are here 3 min
- Secure M365 ✓ Read You are here 3 min
- Windows 10 deadline ✓ Read You are here 4 min
- Audit app access ✓ Read You are here 3 min
- CEO fraud ✓ Read You are here 4 min
- Office 2016 cutoff ✓ Read You are here 3 min
- Patch today ✓ Read You are here 4 min
- Patch VMware ✓ Read You are here 4 min
- Office 2021 EOL ✓ Read You are here 3 min
- Starlink for sites ✓ Read You are here 3 min
- Cardless access ✓ Read You are here 4 min
- Control AI on PCs ✓ Read You are here 4 min
- ScreenConnect flaw ✓ Read You are here 4 min
- Server 2022 EOL ✓ Read You are here 3 min
- Exposed cameras ✓ Read You are here 3 min
- Domain trust fix ✓ Read You are here 4 min
- Patch Cisco ISE ✓ Read You are here 3 min
- Protect the plant ✓ Read You are here 3 min
- Move to 25H2 ✓ Read You are here 4 min
- Outages and UPS ✓ Read You are here 3 min
- IT maintenance ✓ Read You are here 4 min
- Third-party scripts ✓ Read You are here 3 min
- License audit ✓ Read You are here 4 min
- Bajío fiber corridor ✓ Read You are here 3 min
- Check Point flaw ✓ Read You are here 4 min
- Cashless payments ✓ Read You are here 3 min
- AI that hacks alone ✓ Read You are here 3 min
- Field services →