Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Gemini Tricked Into Showing Phishing Message Hidden in Email 

Google Gemini Tricked Into Showing Phishing Message Hidden in Email 

Posted on July 14, 2025July 14, 2025 By CWS

A researcher has discovered that Google Gemini for Workspace is affected by a immediate injection vulnerability that may be exploited to trick the AI assistant into displaying a phishing message.

The weak point was discovered by Marco Figueroa and reported by Mozilla’s 0Din bug bounty program, which focuses on gen-AI vulnerabilities.

The researcher’s hack entails sending the focused person an electronic mail that, along with a benign lure textual content, comprises a phishing message that’s written with white font on a white background, making it invisible to the goal. 

This phishing message, which must be wrapped inside tags, instructs Gemini to incorporate the message on the finish of its response.

When the goal makes use of Gemini’s ‘summarize this electronic mail’ performance to get a abstract of the attacker’s electronic mail, along with a abstract of the textual content seen to the sufferer, Gemini shows the phishing message. That’s as a result of Gemini prioritizes the textual content wrapped in tags and reproduces it verbatim. 

For example, Figueroa created an electronic mail that might trigger Gemini to show a message informing the sufferer that their Gmail password has been compromised, instructing them to name a telephone quantity to reset the password. The attacker might then phish the sufferer’s credentials after they get the decision. 

It’s unclear if the weak point has been addressed by Google. SecurityWeek has reached out to the tech big for remark and can replace this text if it responds. 

The corporate lately summarized a number of the steps it has been taking to mitigate immediate injection assaults. 

Associated: Grok-4 Falls to a Jailbreak Two Days After Its Launch

Associated: ChatGPT Jailbreak: Researchers Bypass AI Safeguards Utilizing Hexadecimal Encoding and EmojisAdvertisement. Scroll to proceed studying.

Associated: New AI Jailbreak Bypasses Guardrails With Ease

Security Week News Tags:Email, Gemini, Google, Hidden, Message, Phishing, Showing, Tricked

Post navigation

Previous Post: New Forensic Technique Uncovers Hidden Trails Left by Hackers Exploiting RDP
Next Post: CitrixBleed 2 Flaw Poses Unacceptable Risk: CISA

Related Posts

Millions of Cars Exposed to Remote Hacking via PerfektBlue Attack Millions of Cars Exposed to Remote Hacking via PerfektBlue Attack Security Week News
Sevii Introduces Predictable AI Defense Costs Sevii Introduces Predictable AI Defense Costs Security Week News
Tenet Security Launches with M Seed Funding for AI Defense Tenet Security Launches with $6M Seed Funding for AI Defense Security Week News
Approov Raises .7 Million for Mobile App Security Approov Raises $6.7 Million for Mobile App Security Security Week News
PwC and Google Cloud Ink 0 Million Deal to Scale AI-Powered Defense PwC and Google Cloud Ink $400 Million Deal to Scale AI-Powered Defense Security Week News
Guardz Banks M Series B for All-in-One SMB Security Guardz Banks $56M Series B for All-in-One SMB Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update
  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Palo Alto Networks Addresses 11 Security Flaws in Latest Update
  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark