AI/ML, Email security

Google Gemini for Workspace at risk of calendar invite compromise

Threat actors could compromise Google Gemini for Workspace instances with the Google Calendar invite with the new Targeted Promptware attack involving indirect prompt injection, reports Hackread.

Malicious Google Calendar invitations with concealed prompts enabled not only the theft of private emails and discovery of users' locations but also the distribution of phishing emails, creation of harmful content, and removal of calendar events, as well as the activation of users' cameras via Zoom, a study by SafeBreach researchers showed. Multiple mobile apps, including those for managing smart home devices, could also be compromised with Targeted Promptware, said researchers, who noted that almost three-quarters of Promptware threats were high-critical risks that could also affect other artificial intelligence-based systems. Google, which has been notified about the attack in February, has already implemented more robust security mechanisms and improved prompt injection attack detection systems to mitigate the threat.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds