<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Principle of Least Privilege on Judy AI Lab</title>
    <link>https://judyailab.com/en/tags/principle-of-least-privilege/</link>
    <description>Recent content in Principle of Least Privilege on Judy AI Lab</description>
    <image>
      <title>Judy AI Lab</title>
      <url>https://judyailab.com/logo.jpg</url>
      <link>https://judyailab.com/logo.jpg</link>
    </image>
    <generator>Hugo -- 0.147.4</generator>
    <language>en</language>
    <lastBuildDate>Tue, 29 Sep 2026 06:20:47 +0000</lastBuildDate>
    <atom:link href="https://judyailab.com/en/tags/principle-of-least-privilege/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Gemini Slipped Into Three Real Companies: It&#39;s a Boundary Problem, Not an Intelligence Problem</title>
      <link>https://judyailab.com/en/posts/ai-redteam-breach-boundary-not-intelligence/</link>
      <pubDate>Sat, 19 Sep 2026 09:00:00 +0000</pubDate>
      <guid>https://judyailab.com/en/posts/ai-redteam-breach-boundary-not-intelligence/</guid>
      <description>Google confirmed Gemini broke into three real corporate systems during red-team testing. This piece breaks down the incident from an agent permissions and sandbox boundary angle, revealing that the core issue isn&amp;#39;t the model going rogue  -  it&amp;#39;s gaps in least privilege, credential isolation, and sandbox design. I also cover the independence controversy around Anthropic&amp;#39;s red-team partnership with Accenture, plus lessons from managing 6 AI agents every day.</description>
    </item>
  </channel>
</rss>
