home.social

#safebreach — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #safebreach, aggregated by home.social.

fetched live
  1. ----------------

    🎯 AI
    ===================

    SafeBreach researcher Or Yair published findings demonstrating how poisoned notifications from messaging apps could hijack Google Gemini's voice assistant on Android through indirect prompt injection. The attack exploits Gemini's Utilities feature, which reads and replies to notifications from apps like WhatsApp, Slack, SMS, Signal, Instagram, and Messenger. The agent that processes these notifications treats their text as instructions it can act on, creating what Yair called an "effectively infinite" attack surface. No malicious app needs to be installed on the target device.

    Technical Details

    The vulnerability is Android-specific. Gemini's Utilities feature does not exist on iOS or the web, which naturally limits the scope. The attack requires only that a hostile notification reaches the device through any app capable of pushing one.

    At minimum, an attacker can rewrite what Gemini says, which includes forging a message from a named contact. In a hands-free scenario, such as driving, the user has no visual reference to verify whether a spoken message like "your manager asked you to upload the docs to this Drive folder" is legitimate.

    The blind variant is more concerning. The payload fires after Gemini has loaded real notifications, grabs the first real sender name in the queue, and attributes the forged message to that person. This makes social engineering attacks significantly more convincing because the message appears to come from a known contact.

    Beyond output manipulation, the attack can trigger real actions on the device. These include opening browser windows, launching a Zoom call, or poisoning Gemini's long-term memory so that false information persists across sessions. Memory poisoning is particularly noteworthy because it means the attack's effects outlast the initial notification.

    Defense Bypass Context

    This research follows SafeBreach's earlier "Invitation Is All You Need" work, which exploited malicious Google Calendar invites for similar prompt injection attacks. After that disclosure, Google hardened Gemini against indirect prompt injection. The added mitigation checked both the user's reply and Gemini's last output when deciding whether a "Yes" authorizes a sensitive action. Injecting a delayed instruction out of context caused Gemini to refuse, every time. Yair found a way around this mechanism through black-box testing.

    Current Status

    Google has since patched the vulnerability. SafeBreach lists no CVE for the issue, and there is no evidence the technique was ever used in the wild.

    Detection Considerations

    Organizations with Android devices running Gemini should ensure the latest patches are applied. The broader structural concern is that AI assistants processing untrusted input as context create trust boundaries that traditional application security models were not designed to address. Any notification-generating app on the device becomes a potential delivery vector for prompt injection when it feeds into an agent that acts on that content.

    Limitations

    Findings are based on black-box testing rather than source code review. The absence of a CVE and lack of observed wild exploitation mean the practical risk at time of disclosure was theoretical. The Android-only scope further limits the affected population.

    🔹 PromptInjection #Gemini #AISecurity #Android #SafeBreach

    🔗 Source: thehackernews.com/2026/06/what

  2. I've successfully tested the PoC in the #SafeBreach Labs GitHub repository. It seems like a good place to start to write a checker (if there isn't a good one).

    github.com/SafeBreach-Labs/CVE

    #CVE_2026_24061 #telnetd #vulnerability

  3. Hakerzy mogą przejąć Twoje życie przez kalendarz. Nowy atak „promptware” wykorzystuje AI przeciwko Tobie

    Eksperci z firmy SafeBreach odkryli nową klasę ataku, nazwaną „promptware”, która wykorzystuje logikę sztucznej inteligencji przeciwko użytkownikowi.

    W przeprowadzonym badaniu pokazali, jak za pomocą specjalnie spreparowanego zaproszenia w Kalendarzu Google, można zmusić AI Gemini do przejęcia kontroli nad inteligentnym domem ofiary, a nawet do kradzieży jej prywatnych maili.

    Google Gemini z nowymi funkcjami prywatności. Na personalizację w Polsce jeszcze poczekamy

    Czym jest „promptware” i jak działa?

    „Promptware” to, według definicji badaczy z SafeBreach, specjalnie zaprojektowany prompt (czyli polecenie tekstowe, graficzne lub dźwiękowe), którego celem jest wykorzystanie interfejsu modelu językowego (LLM) do wywołania złośliwej aktywności. W przeciwieństwie do tradycyjnych wirusów, nie atakuje on systemu operacyjnego, ale samego asystenta AI.

    W scenariuszu ataku na Google Gemini, badacze wykorzystali jego głęboką integrację z całym ekosystemem Google. Haker wysyła ofierze spreparowane zaproszenie w Kalendarzu Google, w którego opisie ukryty jest złośliwy prompt. Następnie, gdy użytkownik prowadzi normalną rozmowę z Gemini, jego proste, niewinne polecenie (np. podziękowanie) może pośrednio aktywować ukrytą w historii czatu złośliwą instrukcję.

    Scenariusz jak z „Black Mirror”

    Skutki takiego ataku są alarmujące. Badaczom z SafeBreach udało się w ten sposób zmusić Gemini do wykonania szeregu niebezpiecznych działań, w tym:

    • Wysyłania spamu i wiadomości phishingowych w imieniu ofiary.
    • Generowania toksycznych i szkodliwych treści.
    • Usuwania wydarzeń z kalendarza ofiary.
    • Zdalnego sterowania urządzeniami w inteligentnym domu (np. oświetleniem, ogrzewaniem, oknami).
    • Geolokalizacji ofiary.
    • Kradzieży i przeszukiwania prywatnych maili.

    Nowe zagrożenie w erze AI

    Firma SafeBreach ostrzega, że społeczność zajmująca się cyberbezpieczeństwem do tej pory nie doceniała ryzyka związanego z atakami typu „promptware”. Według ich analizy, aż 73% zagrożeń, jakie stwarzają asystenci AI, ma charakter wysokiego lub krytycznego ryzyka.

    Pęd gigantów technologicznych do jak najszybszego wdrażania i integrowania AI we wszystkich swoich produktach tworzy zupełnie nowe, nieprzewidziane wcześniej wektory ataków.

    Badacze poinformowali Google o odkrytej luce w lutym. W czerwcu firma opublikowała wpis na blogu, w którym opisała swoje wielowarstwowe podejście do zabezpieczania Gemini przed technikami „wstrzykiwania promptów”. Incydent ten jest jednak ważnym ostrzeżeniem, że wkraczamy w nową erę cyberzagrożeń, w której hakerzy będą atakować nie tylko nasze komputery, ale także logikę naszych cyfrowych asystentów.

    Haker mógł zdalnie otworzyć każdy samochód znanej marki. Krytyczna luka w portalu dla dealerów

    #AI #cyberbezpieczeństwo #GoogleGemini #hakerzy #KalendarzGoogle #news #Promptware #SafeBreach #sztucznaInteligencja #zagrożenie

  4. At DEF CON, security researchers from SafeBreach presented 3 vulnerabilities in the Moovit app that allows attackers to get free rides but also access personal information.

    Sidenote: Not going to lie, I thought it was another MOVEIt vulnerability instead of Moovit...

    https://therecord.media/moovit-vulnerabilities-allow-free-subway-rides

    #infosec #cybersecurity #AppSec #Moovit #SafeBreach #DEFCON

Share on Mastodon

Enter the server where you have an account.