LIVE FEED
FIRST LOOK Google Chrome Shifts to Two-Week Release Cycle for Faster Security Patches // FIRST LOOK Trail of Bits Ships Coop: Isolated VMs for Claude Code and Codex // CRITICAL CVE-2026-81578: PaperCut Exploited by AI Agents at Scale // FIRST LOOK arXiv Research Introduces Self-Evolving Procedural Graphs for LLM Agents // HIGH Chinese AI Firms Accused of Distilling OpenAI and Anthropic Models // HIGH Workflow Identity Hijacking Targets Enterprise AI Data Access // CRITICAL AI-Accelerated WeChat Zero-Click Worm Spreads via RCE // FIRST LOOK Microsoft Uses AI to Ship Record 974-Vulnerability Patch Batch // FIRST LOOK Meta Launches Muse Personal AI Agent with Secure VM Isolation // CRITICAL ChatGPT Cross-Account Data Leakage via Sandbox Channel //
Google Gemini Prompt Injection Powers Smishing Campaign

Google Gemini Prompt Injection Powers Smishing Campaign

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.2 The Hacker News

Google has filed suit against a Chinese cybercrime network operating the Outsider phishing-as-a-service kit, which exploited Gemini AI to generate fraudulent phishing pages and power large-scale SMS phishing attacks against Americans. The network used carefully framed prompts — disguised as benign programming requests — to bypass AI safety controls and produce functional credential-harvesting websites. The case illustrates the growing industrialisation of AI-assisted phishing infrastructure, with over 1.59 million malicious URLs and 100,000 victims attributed to the operation.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.