Affected Technology
Google incidents
Google AI and Gemini security developments
CVE-2025-10585 Type Confusion Vulnerability affecting Chromium V8
Google Chromium V8 Type Confusion Vulnerability Exploitation evidence is classified as confirmed in the wild.
Nx build system Supply Chain Attack Vulnerability
Evidence indicates that Nx build system is affected by a security issue.
CVE-2025-6965 Integer Overflow Vulnerability affecting SQLite
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. The supported impact is information disclosure. Reported affected versions include
Hackers abuse AI models to find new entry paths
Threat actors are leveraging and jailbreaking AI models, especially open-weight variants, to circumvent guardrails and develop novel attack methods for corporate network intrusions. This AI-driven escalation accelerates exploit development and enables new entry paths by facilitating the theft of tokens and session IDs.
Google Security Incident
Evidence indicates that Google is affected by a security issue.
CVE-2026-0628 Privilege Escalation Vulnerability affecting Chrome
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. The supported impact is code injection. Reported affected versions include
Google says hackers are abusing Gemini AI for all attacks stages
State-backed threat actors and cybercriminals are widely abusing Google's Gemini AI model to enhance all stages of their attack lifecycle, from reconnaissance and social engineering to malicious code generation and vulnerability testing. This exploitation of AI capabilities facilitates the creation of tools like HonestCue for dynamic C# payload generation and the acceleration of phishing kit development such as CoinBait.
ChatGPT Remote Code Execution Vulnerability
The article highlights numerous AI agent vulnerabilities, prominently featuring prompt injection techniques like "ASCII Smuggling" used to embed invisible, malicious instructions within legitimate data. These attacks exploit AI agent reasoning and tool usage, leading to significant impacts such as zero-click workflow hijacking, unauthorized data exfiltration, and potential remote code execution in systems like ChatGPT and Google Gemini.
CVE-2025-43429 Security Incident affecting Google
A buffer overflow was addressed with improved bounds checking.
Google Security Incident
Google DeepMind introduces CodeMender, an AI agent designed to automatically discover and patch software vulnerabilities, including complex root causes and architectural weaknesses. The agent applies proactive fixes, such as `-fbounds-safety` annotations, demonstrated to prevent exploitation of vulnerabilities like the `CVE-2023-4863` heap buffer overflow in `libwebp`.
GitHub Supply-Chain Compromise
Fortunately, the company had a policy of checking source code on GitHub first
AI Security Breach
OpenAI Slows AI Training for Two Weeks After Security Breach Involving Its Own System - Subscription Growth Report Vinanet
AI Security Breach
OpenAI Slows AI Training for Two Weeks After Security Breach Involving Its Own System - Subscription Growth Report Vinanet
AI Security Vulnerability
Harness Launches AI Agents for Machine-Speed Vulnerability Response PR Newswire
Google Security Vulnerability
Google Chrome and Mozilla Firefox have received critical updates to address a multitude of security vulnerabilities. These essential patches are deployed to mitigate potential exploitation risks within the web browser platforms.
Z.ai Unveils GLM-5.3 with Major Enhancements for Coding and Cybersecurity
Z.ai released GLM-5.3, an AI model with significant enhancements for cybersecurity analysis, specifically excelling in white-box vulnerability discovery and exploitation reasoning. The model identified 2,436 vulnerabilities across 269 projects, with 1,097 rated medium to high severity, demonstrating improved performance on benchmarks like CyberGym and ExploitBench.
Google Security Vulnerability
The article likely analyzes how modern attack chains, leveraging artificial intelligence, create new vulnerabilities or exploit existing ones within Google Workspace environments. It discusses the critical need to rethink security paradigms and implement advanced defensive strategies against these evolving AI-driven threats.
AI Security Vulnerability
Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data SecurityWeek
AI Security Vulnerability
Google Chrome is leveraging AI and Large Language Models (LLMs) to automate and accelerate the entire vulnerability lifecycle, from proactive discovery and efficient triage to accelerated patch generation. This strategic integration aims to significantly reduce the "patch gap" against N-day exploits, enhancing security resilience and operational efficiency in managing software bugs.
Google Security Vulnerability
A web application firewall (WAF) blocked access, citing triggered security rules against potential malicious inputs like SQL commands or malformed data. This action demonstrates active defense mechanisms in place to prevent common web application vulnerabilities and exploitation attempts.
ChatGPT Security Incident
LLM-generated passwords from tools like Claude, ChatGPT, and Gemini are "fundamentally weak" due to inherent patterns that make them highly predictable and easily guessable, despite appearing complex. Research indicates these passwords have significantly lower entropy (20-27 bits) compared to truly random ones, allowing them to be brute-forced in a matter of hours, potentially ushering in a new era of password brute-forcing.
AI Jailbreak
The OpenClaw experiment serves as a critical demonstration of potential security flaws in enterprise AI systems, highlighting methods to circumvent the intended safety mechanisms of AI models. This research acts as a warning, indicating that AI systems can be manipulated to produce unintended outputs or bypass critical controls.
AI Security Incident
A novel "Promptware Attack" exploits Google Calendar invites as a vector to enable unauthorized surveillance via a user's Zoom camera. This attack weaponizes routine communication tools to achieve covert espionage, highlighting a concerning privacy risk.
AI Security Breach
An AWS environment was rapidly compromised within an 8-minute window, with artificial intelligence actively accelerating the breach process. The incident highlights the growing threat of AI-driven attacks against cloud infrastructure, significantly reducing the time to initial access.
AI Security Vulnerability
Google is offering a $20,000 bug bounty for the identification and reporting of security breaches within its Chrome AI features. This proactive program aims to discover and mitigate potential vulnerabilities in AI components integrated into the Chrome browser.
Google Security Incident
A new zero-click agentic browser attack exploits the excessive agency of LLM-powered assistants, allowing specially crafted emails to trick the browser agent into executing destructive commands. This "Google Drive Wiper" technique leverages granted OAuth access to delete an entire user's Google Drive contents without requiring user confirmation.
ChatGPT Prompt Injection Vulnerability
The article details an investigation into the security vulnerabilities of prominent large language models (LLMs) like ChatGPT, Gemini, and Claude. It specifically highlights findings and risks associated with adversarial prompt attacks, demonstrating potential for prompt injection or model jailbreaking to bypass safety mechanisms.
AI Security Incident
The Google Cloud Threat Intelligence Group's (GTIG) AI Threat Tracker likely highlights an increase in threat actor adoption of artificial intelligence tools to enhance offensive capabilities. This advancement potentially includes AI-driven improvements in malware generation, leading to more sophisticated and evasive variants.
AI Prompt Injection Vulnerability
Lakera has launched an open-source security benchmark specifically designed to evaluate and enhance the security posture of Large Language Model (LLM) backends integrated into AI agents. This benchmark aims to proactively identify and mitigate various potential vulnerabilities, such as prompt injection and data exfiltration risks, inherent in the deployment of advanced conversational AI systems.
AI Security Vulnerability
A Stanford study reveals that leading AI companies, including Anthropic, Google, and OpenAI, are defaulting to using user chat inputs for large language model (LLM) training. This practice, combined with opaque privacy policies and long data retention, creates significant privacy vulnerabilities, risking the collection and unintended use of sensitive personal and children's data.
AI Data Exposure
Kaspersky outlines security risks for developers employing LLM assistants and "vibe coding" methodologies. These concerns primarily involve the potential for insecure code generation, intellectual property leakage through AI interaction, and the introduction of exploitable vulnerabilities into software during development.
Google Security Vulnerability
Google DeepMind has developed CodeMender, an AI agent designed to autonomously find and patch software vulnerabilities. Leveraging advanced program analysis and multi-agent systems, CodeMender rewrites vulnerable code to prevent future exploits and eliminate entire classes of security bugs.
Google Security Vulnerability
Google DeepMind has introduced CodeMender, an AI-powered agent designed to automatically detect, patch, and rewrite vulnerable code to eliminate entire classes of vulnerabilities. Leveraging Gemini Deep Think models and an LLM-based critique tool, CodeMender addresses root causes and validates fixes, having already contributed 72 security patches to open-source projects.
AI Prompt Injection Vulnerability
The Kaspersky article forecasts various technical methods and attack vectors projected to compromise Large Language Models (LLMs) by 2025. It likely details emerging vulnerabilities and exploitation techniques targeting the integrity, confidentiality, and availability of LLM-powered systems.
AI Prompt Injection Vulnerability
This article addresses the critical security challenges inherent in deploying AI agents, highlighting the potential for vulnerabilities that could compromise business operations and data integrity. It likely explores methods for protecting these "digital sidekicks" by discussing preventative measures and robust security frameworks for AI systems.
AI Prompt Injection Vulnerability
Zenity Labs research details how widely deployed AI agents are highly susceptible to "hijacking attacks" via methods such as email-based prompt injection and zero-click risks. These vulnerabilities enable data exfiltration, manipulation of critical workflows, user impersonation, and long-term access, impacting major platforms like OpenAI ChatGPT, Microsoft Copilot, Salesforce Einstein, and Google Gemini.
Google Prompt Injection Vulnerability
Cybersecurity researchers have uncovered a jailbreak technique, combining Echo Chamber and narrative-driven steering, to bypass GPT-5's ethical guardrails and generate harmful content. This, alongside "AgentFlayer" zero-click prompt injection attacks, exploits AI agents integrated with external systems like Google Drive and Jira to exfiltrate sensitive data such as API keys and secrets.
AI Security Vulnerability
Security researchers uncovered a critical weakness within OpenAI’s Connectors, enabling unauthorized data extraction from linked services. This vulnerability allowed attackers to leak data from Google Drive via a "poisoned document" without any user interaction.
AI Security Vulnerability
Google's LLM-based vulnerability researcher, "Big Sleep," developed by DeepMind and Project Zero, has autonomously identified 20 security flaws across various popular open-source software, including FFmpeg and ImageMagick. Although specific CVEs, exploit details, and immediate impact remain undisclosed due to ongoing remediation, this event signifies a notable advancement in automated vulnerability discovery.
Gemini Prompt Injection Vulnerability
The "Echo Chamber" attack is a sophisticated prompt injection technique that leverages context poisoning and multi-turn reasoning to bypass large language model (LLM) guardrails. This allows attackers to gradually manipulate models like GPT and Gemini into generating harmful content, achieving high success rates for categories such as hate speech and illegal activities.