Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data 

Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data 

Posted on December 10, 2025December 11, 2025 By CWS

Google lately addressed a Gemini Enterprise vulnerability that would have been exploited by risk actors to acquire probably delicate company information, in line with AI safety agency Noma Safety.

Dubbed GeminiJack, the assault methodology didn’t require any consumer interplay. Sending a specifically crafted doc, calendar invite, or e mail was sufficient to use the flaw, which Noma described as “an architectural weak spot in the best way enterprise AI techniques interpret info”.

Gemini Enterprise is an agentic platform designed to allow giant organizations to automate complicated, multi-step enterprise workflows throughout their complete expertise stack.

GeminiJack leveraged the truth that Gemini Enterprise has entry to varied Google companies utilized by a corporation, together with Gmail, Docs, Calendar, and different Workspace elements.

An attacker might have integrated hidden immediate injection directions right into a specifically crafted e mail, doc, or calendar invitation. The sufferer wouldn’t must view the malicious asset; as a substitute, the attacker’s instructions could be executed by Gemini Enterprise when being requested for info on a associated subject.

“An attacker might share a Google Doc together with oblique immediate injection about budgets with out notification,” Noma defined. “Later, when any worker carried out an ordinary search in Gemini Enterprise, reminiscent of ‘present me our budgets’, the AI mechanically retrieved the poisoned doc and executed the directions.”

Whereas the worker bought the data they requested from Gemini, the AI could be instructed to silently exfiltrate emails, calendar entries, or company paperwork. 

The attacker might have, for example, instructed Gemini to gather all paperwork containing the phrases “confidential”, “authorized”, “wage”, or “API key”.Commercial. Scroll to proceed studying.

In response to Noma, the problem was reported to Google in Might, and complete mitigations had been rolled out in current weeks. 

Google has confirmed to SecurityWeek that Noma’s description of the findings is correct and that the vulnerability has been mitigated.

Cybersecurity firms usually uncover such oblique immediate injection assaults and reveal them in opposition to gen-AI merchandise reminiscent of Claude, Gemini, and ChatGPT. 

Associated: AI Techniques Susceptible to Immediate Injection through Picture Scaling Assault

Associated: WormGPT 4 and KawaiiGPT: New Darkish LLMs Increase Cybercrime Automation

Associated: SquareX and Perplexity Quarrel Over Alleged Comet Browser Vulnerability

Security Week News Tags:Corporate, Data, Enterprise, Exposing, Gemini, Google, Patches, Vulnerability

Post navigation

Previous Post: Fortinet Patches Critical Authentication Bypass Vulnerabilities
Next Post: Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling

Related Posts

Cisco Patches Critical Vulnerabilities in Contact Center Appliance Cisco Patches Critical Vulnerabilities in Contact Center Appliance Security Week News
Cisco Patches 35 Vulnerabilities Across Several Products Cisco Patches 35 Vulnerabilities Across Several Products Security Week News
High-Severity Vulnerabilities Patched in Chrome, Firefox High-Severity Vulnerabilities Patched in Chrome, Firefox Security Week News
Thousands of Secrets Leaked on Code Formatting Platforms Thousands of Secrets Leaked on Code Formatting Platforms Security Week News
Qantas Data Breach Impacts Up to 6 Million Customers  Qantas Data Breach Impacts Up to 6 Million Customers  Security Week News
European Airport Disruptions Caused by Ransomware Attack European Airport Disruptions Caused by Ransomware Attack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark