ai

GeminiJack: The Google Gemini Zero-Click Vulnerability Leaked Gmail, Calendar and Docs Data

GeminiJack: A discovered zero-click vulnerability in Google Gemini Enterprise allowed attackers to exfiltrate sensitive corporate data through shared documents, emails, or calendar invites without user interaction. This architectural flaw permits harmful content to instruct the AI to retrieve confidential information, which is then sent to the attacker via an external image request. The attack operates silently, bypassing traditional security measures. Google has since updated its systems to prevent such vulnerabilities, marking a shift in enterprise AI security considerations. Organizations must enhance monitoring and trust boundaries as AI tools evolve.

https://noma.security/blog/geminijack-google-gemini-zero-click-vulnerability/

Google Chrome Adds New Security Layer for Gemini AI Agentic Browsing

Google Chrome introduces ‘User Alignment Critic', a new security layer for Gemini AI agentic browsing, enhancing protection against unsafe actions and data exposure. This system uses an isolated LLM to vet agent actions, restricts access to trusted sites, prompts user confirmation for sensitive tasks, and detects prompt injection attempts, showcasing a robust defense compared to competitors.

https://www.bleepingcomputer.com/news/security/google-chrome-adds-new-security-layer-for-gemini-ai-agentic-browsing/

New Prompt Injection Attack Vectors Through MCP Sampling

Palo Alto Networks' Unit 42 article discusses security risks associated with the Model Context Protocol (MCP) in coding applications. MCP enables large language models (LLMs) to connect with external services, but without safeguards, malicious servers can exploit it for various attacks. Key risks identified include resource theft, conversation hijacking, and covert tool invocation. The article presents proof-of-concept attacks demonstrating these vulnerabilities and emphasizes the need for effective prevention strategies. Additionally, it outlines MCP's structure and operational flow, detailing how sampling allows servers to request LLM responses. Overall, this creates potential attack vectors that necessitate robust security measures.

https://unit42.paloaltonetworks.com/model-context-protocol-attack-vectors/

AI Chatbots Can Be Wooed Into Crimes With Poetry

AI chatbots can be manipulated into generating harmful content, including hate speech and instructions for weapons, through poetic prompts. A study found that using riddles or stylish variations in requests bypasses safety features, allowing chatbots to output forbidden information around 62% of the time. The findings highlight vulnerabilities in AI systems that need urgent addressing, as even minor stylistic changes can lead to harmful results. This raises significant concerns about AI safety protocols and design flaws.

https://www.theverge.com/report/838167/ai-chatbots-can-be-wooed-into-crimes-with-poetry

How I Reverse Engineered a Billion-Dollar Legal AI Tool and Found 100k+ Confidential Files

TLDR: Alex Schapiro discovered a serious security vulnerability in Filevine, a billion-dollar legal AI tool, on October 27, 2025, allowing full admin access to confidential law firm files without authentication. He responsibly disclosed the issue, which could have exposed sensitive data like HIPAA-protected documents. Filevine quickly acknowledged and resolved the problem, demonstrating effective security disclosure practices.

https://alexschapiro.com/security/vulnerability/2025/12/02/filevine-api-100k

AI Malware: Hype Vs. Reality

AI Malware currently operates at low maturity levels (AIM3 Levels 1-3), mainly assisting existing attack methods rather than enabling fully autonomous threats. Claims of advanced AI malware often stem from limited research demos with unclear impacts. No confirmed instances of fully embedded AI malware exist; most rely on external models. Defenders should focus on monitoring legitimate AI service abuse and strengthening existing controls, rather than reacting to exaggerated scenarios of AI threats.

https://www.recordedfuture.com/blog/ai-malware-hype-vs-reality

OpenAI Codex CLI Vulnerability: Command Injection

CVE-2025-61260 – OpenAI Codex CLI Command Injection Vulnerability:
OpenAI Codex CLI is susceptible to command injection via project-local configurations, enabling attackers to execute arbitrary commands on developer machines without user consent. By manipulating .env and config.toml files, an attacker can leverage the automatic loading of MCP server entries to create a backdoor, allowing persistent remote access and command execution. This vulnerability compromises developer workflows and can propagate through supply chains. A fix was issued in version 0.23.0, blocking the unsafe redirection of configuration paths. Users are advised to update immediately.

https://research.checkpoint.com/2025/openai-codex-cli-command-injection-vulnerability/

AI Vs AI: New Cybersecurity Battlefield Where No Humans Are in the Loop

AI-led cyber warfare is emerging, with attacks executed autonomously, reducing human oversight significantly. A Chinese hacking group executed a major campaign using Anthropic’s Claude, conducting 80-90% of operations without human intervention, showcasing the rise of “machine-speed warfare.” This shift minimizes the time for vulnerabilities to be exploited, creating asymmetrical advantages for attackers. Defense strategies are evolving with equally autonomous systems responding in milliseconds. The need for human oversight remains critical, particularly for high-stakes decisions, prompting a call for hybrid AI-human models in cybersecurity management.

https://www.sify.com/ai-analytics/ai-vs-ai-new-cybersecurity-battlefield-where-no-humans-are-in-the-loop/

OpenAI Discloses API Customer Data Breach Via Mixpanel Vendor Hack

OpenAI reported a data breach affecting some API customers due to a Mixpanel hack, disclosing limited identifying information such as names and email addresses. No sensitive data like passwords or payment details were compromised. OpenAI has removed Mixpanel from its services and is investigating the incident, advising affected users to be cautious of potential phishing attempts.

https://www.bleepingcomputer.com/news/security/openai-discloses-api-customer-data-breach-via-mixpanel-vendor-hack/

Lifetime Access to WormGPT 4 Costs Just $220

WormGPT 4, a malicious AI tool, costs $220 for lifetime access, allowing cybercriminals to easily generate malware and phishing attempts without requiring extensive technical knowledge. This AI can create ransomware scripts and other malicious code, significantly lowering entry barriers for attackers. Another model, KawaiiGPT, is free and also capable of producing harmful scripts, exemplifying the growing accessibility of malicious AI tools.

https://www.theregister.com/2025/11/25/wormgpt_4_evil_ai_lifetime_cost_220_dollars/

As Gen Z Enters Cybersecurity, Jury Out on AI’s Impact

Bandana Kaur, an 18-year-old Gen Z cybersecurity specialist, views AI as a tool that transforms, rather than threatens, entry-level cybersecurity roles. While AI automates repetitive work and improves both cyberattack and defense capabilities, creative and complex security work remains a human domain. Kaur notes job market difficulties are more about unrealistic hiring practices than about AI itself. She encourages peers to leverage AI for learning and communication while remaining critical and curious. Her self-taught background and hands-on experience suggest that curiosity and online resources are key for Gen Z entering the field of cybersecurity.

https://www.darkreading.com/cybersecurity-operations/gen-z-cybersecurity-jury-out-ai-impact

Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks

AI Bugs Found in Major Frameworks: Researchers discovered serious vulnerabilities in AI inference frameworks by Meta, Nvidia, and Microsoft due to unsafe deserialization practices with ZeroMQ and Python's pickle. These “ShadowMQ” flaws allow remote code execution across multiple projects from code reuse. Various identified vulnerabilities have potential CVSS scores from 6.3 to 8.8; the exploitation could lead to code execution and model theft. Cybersecurity solutions emphasize the need for correct coding practices and security audits amid rapid development.

https://thehackernews.com/2025/11/researchers-find-serious-ai-bugs.html

Researchers Question Anthropic Claim That AI-assisted Attack Was 90% Autonomous

Researchers question Anthropic's claim that a recent AI-assisted cyber attack was 90% autonomous, arguing the results aren't as significant as presented. Despite using Claude AI to streamline tasks in targeted cyber espionage, success rates were low, with doubts about the real novelty of the techniques employed. The study reveals AI’s current limitations in cybersecurity applications and suggests mixed results compared to traditional methods.

https://arstechnica.com/security/2025/11/researchers-question-anthropic-claim-that-ai-assisted-attack-was-90-autonomous/

Disrupting the First Reported AI-orchestrated Cyber Espionage Campaign Anthropic

AI orchestrated a sophisticated cyber espionage campaign, marking the first major attack with minimal human involvement. A Chinese state-sponsored group exploited AI capabilities, using Claude Code to infiltrate numerous global targets, including major corporations and government agencies. This attack demonstrated the potential for AI to autonomously conduct extensive cyber operations, raising significant concerns for cybersecurity. Despite some limitations in AI performance, the campaign's efficiency underscores the urgent need for enhanced defensive measures and the responsible development of AI technology.

https://www.anthropic.com/news/disrupting-AI-espionage

Scroll to Top