Google Gemini CLI abused as a hacking agent, malware botnet operator
|
submitted by /u/CyberMasterV [comments] |
|
submitted by /u/CyberMasterV [comments] |
Cloud security firm Sysdig has released details on what it claims to be the world’s first ransomware campaign completely driven by a large language model (LLM). Dubbed JadePuffer, the campaign targeted an internet-facing Langflow instance by exploiting CVE-2025-3248. It then ran “an adaptive and fully automated campaign” which resulted in “a destructive database-extortion playbook against the victim’s production database…
Authored by Neil Tyagi Executive Summary McAfee Advanced Threat Research has identified an active browser-extension campaign designed to steal cryptocurrency by silently substituting wallet addresses the moment a user initiates a transaction. The campaign is delivered through unsigned installers — observed in both .NET and Golang variants — that deploy a malicious Chromium extension masquerading as a benign “Google Notes” utility. …
( July 22, 2026, 13:17 GMT | Official Statement) — MLex Summary: The Italian privacy watchdog has issued four fines totaling €7.72 million to companies using an automated scoring system that decided whether potential customers would get a gas or electricity contract based on reliability. The method for calculating that score was unclear, violating principles…
There’s a broad consensus among AI researchers: prompt injection has no reliable fix. LLMs will always struggle to tell commands from the data they’re processing. That leaves attackers and defenders locked in an endless game of cat and mouse, where every new filter meant to protect an AI system gets bypassed by an even more…
An ongoing threat campaign distributing an advanced Python-based malware named NarwhalRAT, which initiates through targeted spear-phishing emails masquerading as urgent security notifications from the official Microsoft Account Team. These deceptive messages warn recipients of abnormal one-time password generation and urge them to review an attached security advisory. Analysts from IntCyberDigest note that this social engineering…
American soft drinks giant Coca-Cola announced Thursday that it has suspended production at its subsidiary Fairlife after detecting a ransomware attack. Based in Chicago, Fairlife is a Coca-Cola wholly owned dairy company that distributes ultra-filtered milk in five flavors: chocolate, fat-free, reduced fat, strawberry, and whole milk. In a July 16 filing with the US…