Phishing, AI/ML

Phishing potentially facilitated by Google Gemini exploitation

Privacy concept: computer keyboard with Key icon and word Phishing on enter button background, 3d render

Malicious email summaries with warnings directing to phishing sites could be generated using Google Gemini for Workspace, BleepingComputer reports.

Attacks commence with the creation of an email with a concealed order, which would be parsed and obeyed by Gemini upon the victim's prompting of an email summary generation, according to Mozilla GenAI Bug Bounty Programs Manager Marco Figueroa, who reported the issue through Mozilla's 0din program. Such a new attack technique could be combated either through the removal and disregard of messages hidden in the email or the adoption of a post-processing filter that would flag potentially malicious content within Gemini-generated summaries, said Figueroa. Meanwhile, Google has noted that there has been no indication of Gemini manipulation as discovered by Figueroa, while emphasizing its defenses against prompt injection intrusions. "We are constantly hardening our already robust defenses through red-teaming exercises that train our models to defend against these types of adversarial attacks," said a Google spokesperson.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds