Affected Technology

Google incidents

Google AI and Gemini security developments

Matching incidents

40

Technology type

Vendor

Medium severity STABLE

CVE-2026-0628 Privilege Escalation Vulnerability affecting Chrome

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. The supported impact is code injection. Reported affected versions include

GoogleChromeGeminiGemini AI panelRemote Code ExecutionCVE-2026-0628
1 source: darkreading.com Updated 5mo ago
News STABLE

Google says hackers are abusing Gemini AI for all attacks stages

State-backed threat actors and cybercriminals are widely abusing Google's Gemini AI model to enhance all stages of their attack lifecycle, from reconnaissance and social engineering to malicious code generation and vulnerability testing. This exploitation of AI capabilities facilitates the creation of tools like HonestCue for dynamic C# payload generation and the acceleration of phishing kit development such as CoinBait.

GoogleCoinBaitGeminiGemini AIHonestCuecybercriminals
Low severity STABLE

ChatGPT Remote Code Execution Vulnerability

The article highlights numerous AI agent vulnerabilities, prominently featuring prompt injection techniques like "ASCII Smuggling" used to embed invisible, malicious instructions within legitimate data. These attacks exploit AI agent reasoning and tool usage, leading to significant impacts such as zero-click workflow hijacking, unauthorized data exfiltration, and potential remote code execution in systems like ChatGPT and Google Gemini.

1 source: aimultiple.com Updated 6mo ago
Low severity STABLE

Google Security Incident

Google DeepMind introduces CodeMender, an AI agent designed to automatically discover and patch software vulnerabilities, including complex root causes and architectural weaknesses. The agent applies proactive fixes, such as `-fbounds-safety` annotations, demonstrated to prevent exploitation of vulnerabilities like the `CVE-2023-4863` heap buffer overflow in `libwebp`.

GoogleAI AgentsIntroducing CodeMender
1 source: deepmind.google Updated 10mo ago
Low severity NEW

Google Security Vulnerability

Google Chrome and Mozilla Firefox have received critical updates to address a multitude of security vulnerabilities. These essential patches are deployed to mitigate potential exploitation risks within the web browser platforms.

GoogleChromeDozensFirefox Updates Patch
Low severity STABLE

Z.ai Unveils GLM-5.3 with Major Enhancements for Coding and Cybersecurity

Z.ai released GLM-5.3, an AI model with significant enhancements for cybersecurity analysis, specifically excelling in white-box vulnerability discovery and exploitation reasoning. The model identified 2,436 vulnerabilities across 269 projects, with 1,097 rated medium to high severity, demonstrating improved performance on benchmarks like CyberGym and ExploitBench.

Low severity NEW

Google Security Vulnerability

The article likely analyzes how modern attack chains, leveraging artificial intelligence, create new vulnerabilities or exploit existing ones within Google Workspace environments. It discusses the critical need to rethink security paradigms and implement advanced defensive strategies against these evolving AI-driven threats.

GoogleAgeChainRethinking Google WorkspaceThe Modern Attack
Low severity STABLE

AI Security Vulnerability

Google Chrome is leveraging AI and Large Language Models (LLMs) to automate and accelerate the entire vulnerability lifecycle, from proactive discovery and efficient triage to accelerated patch generation. This strategic integration aims to significantly reduce the "patch gap" against N-day exploits, enhancing security resilience and operational efficiency in managing software bugs.

1 source: blog.google Updated 21d ago
Low severity STABLE

Google Security Vulnerability

A web application firewall (WAF) blocked access, citing triggered security rules against potential malicious inputs like SQL commands or malformed data. This action demonstrates active defense mechanisms in place to prevent common web application vulnerabilities and exploitation attempts.

GoogleDay ExploitGenerated ZeroGoogle Detects First
1 source: securityweek.com Updated 3mo ago
Low severity STABLE

ChatGPT Security Incident

LLM-generated passwords from tools like Claude, ChatGPT, and Gemini are "fundamentally weak" due to inherent patterns that make them highly predictable and easily guessable, despite appearing complex. Research indicates these passwords have significantly lower entropy (20-27 bits) compared to truly random ones, allowing them to be brute-forced in a matter of hours, potentially ushering in a new era of password brute-forcing.

1 source: theregister.com Updated 6mo ago
Low severity STABLE

AI Jailbreak

The OpenClaw experiment serves as a critical demonstration of potential security flaws in enterprise AI systems, highlighting methods to circumvent the intended safety mechanisms of AI models. This research acts as a warning, indicating that AI systems can be manipulated to produce unintended outputs or bypass critical controls.

1 source: news.google.com Updated 6mo ago
Low severity STABLE

AI Security Incident

A novel "Promptware Attack" exploits Google Calendar invites as a vector to enable unauthorized surveillance via a user's Zoom camera. This attack weaponizes routine communication tools to achieve covert espionage, highlighting a concerning privacy risk.

1 source: cyberpress.org Updated 6mo ago
Low severity STABLE

AI Security Breach

An AWS environment was rapidly compromised within an 8-minute window, with artificial intelligence actively accelerating the breach process. The incident highlights the growing threat of AI-driven attacks against cloud infrastructure, significantly reducing the time to initial access.

1 source: news.google.com Updated 6mo ago
Low severity STABLE

AI Security Vulnerability

Google is offering a $20,000 bug bounty for the identification and reporting of security breaches within its Chrome AI features. This proactive program aims to discover and mitigate potential vulnerabilities in AI components integrated into the Chrome browser.

1 source: eweek.com Updated 8mo ago
Low severity STABLE

Google Security Incident

A new zero-click agentic browser attack exploits the excessive agency of LLM-powered assistants, allowing specially crafted emails to trick the browser agent into executing destructive commands. This "Google Drive Wiper" technique leverages granted OAuth access to delete an entire user's Google Drive contents without requiring user confirmation.

GoogleAI AgentsAttack Can DeleteClick Agentic BrowserEntire Google DriveUsing Crafted Emails
1 source: thehackernews.com Updated 8mo ago
Low severity STABLE

AI Security Incident

The Google Cloud Threat Intelligence Group's (GTIG) AI Threat Tracker likely highlights an increase in threat actor adoption of artificial intelligence tools to enhance offensive capabilities. This advancement potentially includes AI-driven improvements in malware generation, leading to more sophisticated and evasive variants.

1 source: news.google.com Updated 9mo ago
Low severity STABLE

AI Prompt Injection Vulnerability

Lakera has launched an open-source security benchmark specifically designed to evaluate and enhance the security posture of Large Language Model (LLM) backends integrated into AI agents. This benchmark aims to proactively identify and mitigate various potential vulnerabilities, such as prompt injection and data exfiltration risks, inherent in the deployment of advanced conversational AI systems.

1 source: news.google.com Updated 9mo ago
Low severity STABLE

AI Security Vulnerability

A Stanford study reveals that leading AI companies, including Anthropic, Google, and OpenAI, are defaulting to using user chat inputs for large language model (LLM) training. This practice, combined with opaque privacy policies and long data retention, creates significant privacy vulnerabilities, risking the collection and unintended use of sensitive personal and children's data.

1 source: hai.stanford.edu Updated 10mo ago
Low severity STABLE

AI Data Exposure

Kaspersky outlines security risks for developers employing LLM assistants and "vibe coding" methodologies. These concerns primarily involve the potential for insecure code generation, intellectual property leakage through AI interaction, and the introduction of exploitable vulnerabilities into software during development.

1 source: news.google.com Updated 10mo ago
Low severity STABLE

Google Security Vulnerability

Google DeepMind has developed CodeMender, an AI agent designed to autonomously find and patch software vulnerabilities. Leveraging advanced program analysis and multi-agent systems, CodeMender rewrites vulnerable code to prevent future exploits and eliminate entire classes of security bugs.

GoogleAI AgentsFindsFixes VulnerabilitiesGoogle DeepMindNew AI Agent
1 source: securityweek.com Updated 10mo ago
Low severity STABLE

Google Security Vulnerability

Google DeepMind has introduced CodeMender, an AI-powered agent designed to automatically detect, patch, and rewrite vulnerable code to eliminate entire classes of vulnerabilities. Leveraging Gemini Deep Think models and an LLM-based critique tool, CodeMender addresses root causes and validates fixes, having already contributed 72 security patches to open-source projects.

GoogleGeminiAI AgentsRemote Code ExecutionIt Rewrites CodeJust Find Vulnerabilities
1 source: thehackernews.com Updated 10mo ago
Low severity STABLE

AI Prompt Injection Vulnerability

The Kaspersky article forecasts various technical methods and attack vectors projected to compromise Large Language Models (LLMs) by 2025. It likely details emerging vulnerabilities and exploitation techniques targeting the integrity, confidentiality, and availability of LLM-powered systems.

1 source: news.google.com Updated 11mo ago
Low severity STABLE

AI Prompt Injection Vulnerability

This article addresses the critical security challenges inherent in deploying AI agents, highlighting the potential for vulnerabilities that could compromise business operations and data integrity. It likely explores methods for protecting these "digital sidekicks" by discussing preventative measures and robust security frameworks for AI systems.

1 source: news.google.com Updated 11mo ago
Low severity STABLE

AI Prompt Injection Vulnerability

Zenity Labs research details how widely deployed AI agents are highly susceptible to "hijacking attacks" via methods such as email-based prompt injection and zero-click risks. These vulnerabilities enable data exfiltration, manipulation of critical workflows, user impersonation, and long-term access, impacting major platforms like OpenAI ChatGPT, Microsoft Copilot, Salesforce Einstein, and Google Gemini.

Low severity STABLE

Google Prompt Injection Vulnerability

Cybersecurity researchers have uncovered a jailbreak technique, combining Echo Chamber and narrative-driven steering, to bypass GPT-5's ethical guardrails and generate harmful content. This, alongside "AgentFlayer" zero-click prompt injection attacks, exploits AI agents integrated with external systems like Google Drive and Jira to exfiltrate sensitive data such as API keys and secrets.

GoogleAI AgentsJailbreakingPrompt InjectionAttacks Exposing CloudClick AI Agent
Low severity STABLE

AI Security Vulnerability

Google's LLM-based vulnerability researcher, "Big Sleep," developed by DeepMind and Project Zero, has autonomously identified 20 security flaws across various popular open-source software, including FFmpeg and ImageMagick. Although specific CVEs, exploit details, and immediate impact remain undisclosed due to ongoing remediation, this event signifies a notable advancement in automated vulnerability discovery.

1 source: techcrunch.com Updated 1y ago
Low severity STABLE

Gemini Prompt Injection Vulnerability

The "Echo Chamber" attack is a sophisticated prompt injection technique that leverages context poisoning and multi-turn reasoning to bypass large language model (LLM) guardrails. This allows attackers to gradually manipulate models like GPT and Gemini into generating harmful content, achieving high success rates for categories such as hate speech and illegal activities.

GoogleGeminiJailbreakingPrompt InjectionAI GuardrailsAttack Blows Past

Back to intelligence feed