Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data 

Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data 

Posted on December 10, 2025December 11, 2025 By CWS

Google lately addressed a Gemini Enterprise vulnerability that would have been exploited by risk actors to acquire probably delicate company information, in line with AI safety agency Noma Safety.

Dubbed GeminiJack, the assault methodology didn’t require any consumer interplay. Sending a specifically crafted doc, calendar invite, or e mail was sufficient to use the flaw, which Noma described as “an architectural weak spot in the best way enterprise AI techniques interpret info”.

Gemini Enterprise is an agentic platform designed to allow giant organizations to automate complicated, multi-step enterprise workflows throughout their complete expertise stack.

GeminiJack leveraged the truth that Gemini Enterprise has entry to varied Google companies utilized by a corporation, together with Gmail, Docs, Calendar, and different Workspace elements.

An attacker might have integrated hidden immediate injection directions right into a specifically crafted e mail, doc, or calendar invitation. The sufferer wouldn’t must view the malicious asset; as a substitute, the attacker’s instructions could be executed by Gemini Enterprise when being requested for info on a associated subject.

“An attacker might share a Google Doc together with oblique immediate injection about budgets with out notification,” Noma defined. “Later, when any worker carried out an ordinary search in Gemini Enterprise, reminiscent of ‘present me our budgets’, the AI mechanically retrieved the poisoned doc and executed the directions.”

Whereas the worker bought the data they requested from Gemini, the AI could be instructed to silently exfiltrate emails, calendar entries, or company paperwork. 

The attacker might have, for example, instructed Gemini to gather all paperwork containing the phrases “confidential”, “authorized”, “wage”, or “API key”.Commercial. Scroll to proceed studying.

In response to Noma, the problem was reported to Google in Might, and complete mitigations had been rolled out in current weeks. 

Google has confirmed to SecurityWeek that Noma’s description of the findings is correct and that the vulnerability has been mitigated.

Cybersecurity firms usually uncover such oblique immediate injection assaults and reveal them in opposition to gen-AI merchandise reminiscent of Claude, Gemini, and ChatGPT. 

Associated: AI Techniques Susceptible to Immediate Injection through Picture Scaling Assault

Associated: WormGPT 4 and KawaiiGPT: New Darkish LLMs Increase Cybercrime Automation

Associated: SquareX and Perplexity Quarrel Over Alleged Comet Browser Vulnerability

Security Week News Tags:Corporate, Data, Enterprise, Exposing, Gemini, Google, Patches, Vulnerability

Post navigation

Previous Post: Fortinet Patches Critical Authentication Bypass Vulnerabilities
Next Post: Three PCIe Encryption Weaknesses Expose PCIe 5.0+ Systems to Faulty Data Handling

Related Posts

700Credit Data Breach Impacts 5.8 Million Individuals 700Credit Data Breach Impacts 5.8 Million Individuals Security Week News
Aanchal Gupta Joins Adobe as Chief Security Officer Aanchal Gupta Joins Adobe as Chief Security Officer Security Week News
Pierce County Library Data Breach Impacts 340,000 Pierce County Library Data Breach Impacts 340,000 Security Week News
MainStreet Bank Data Breach Impacts Customer Payment Cards  MainStreet Bank Data Breach Impacts Customer Payment Cards  Security Week News
Google Fortifies Chrome Agentic AI Against Indirect Prompt Injection Attacks Google Fortifies Chrome Agentic AI Against Indirect Prompt Injection Attacks Security Week News
China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear China-Linked Hackers Exploiting Zero-Day in Cisco Security Gear Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News