News report
Google says hackers are abusing Gemini AI for all attacks stages
State-backed threat actors and cybercriminals are widely abusing Google's Gemini AI model to enhance all stages of their attack lifecycle, from reconnaissance and social engineering to malicious code generation and vulnerability testing. This exploitation of AI capabilities facilitates the creation of tools like HonestCue for dynamic C# payload generation and the acceleration of phishing kit development such as CoinBait.
What Happened
State-backed threat actors and cybercriminals are widely abusing Google's Gemini AI model to enhance all stages of their attack lifecycle, from reconnaissance and social engineering to malicious code generation and vulnerability testing. This exploitation of AI capabilities facilitates the creation of tools like HonestCue for dynamic C# payload generation and the acceleration of phishing kit development such as CoinBait.
Why This Matters
This is source reporting of a security event, not a confirmed product vulnerability or patchable CVE. Use it as situational awareness if named organizations, cloud tenants, or identity systems overlap with yours.
Recommended Action
Read the source report. Confirm whether any named organizations, identity tenants, or cloud environments you operate are implicated. Do not treat this as a vendor advisory unless a CVE or official bulletin is attached.
Exposure
Exposure unknown
Feb 12, 2026 05:30
Exposure reason: This incident does not currently match a technology in My AI Stack.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Feb 12, 2026 05:30BugSkan first recorded this incident.
-
Google says hackers are abusing Gemini AI for all attacks stages - BleepingComputer
Feb 12, 2026 05:30bleepingcomputer.com · News
Sources
bleepingcomputer.com · Feb 12, 2026 05:30
State-backed threat actors and cybercriminals are widely abusing Google's Gemini AI model to enhance all stages of their attack lifecycle, from reconnaissance and social engineering to malicious code generation and vulnerability testing. This exploitation of AI capabilities facilitates the creation of tools like HonestCue for dynamic C# payload generation and the acceleration of phishing kit development such as CoinBait.
Open publisher sourceMy AI Stack Match
Create an account to see which incidents overlap with your AI stack.