LIVE FEED
FIRST LOOK Google Chrome Shifts to Two-Week Release Cycle for Faster Security Patches // FIRST LOOK Trail of Bits Ships Coop: Isolated VMs for Claude Code and Codex // CRITICAL CVE-2026-81578: PaperCut Exploited by AI Agents at Scale // FIRST LOOK arXiv Research Introduces Self-Evolving Procedural Graphs for LLM Agents // HIGH Chinese AI Firms Accused of Distilling OpenAI and Anthropic Models // HIGH Workflow Identity Hijacking Targets Enterprise AI Data Access // CRITICAL AI-Accelerated WeChat Zero-Click Worm Spreads via RCE // FIRST LOOK Microsoft Uses AI to Ship Record 974-Vulnerability Patch Batch // FIRST LOOK Meta Launches Muse Personal AI Agent with Secure VM Isolation // CRITICAL ChatGPT Cross-Account Data Leakage via Sandbox Channel //
Google Gemini Abused for Phishing-as-a-Service

Google Gemini Abused for Phishing-as-a-Service

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.2 Schneier on Security

A Chinese cybercriminal group called Outsider Enterprise exploited Google's Gemini AI to mass-produce phishing pages impersonating Google, YouTube, and government agencies like E-ZPass, offering nearly 300 scam templates via Telegram. Google has filed suit and coordinated with major US carriers to block the resulting smishing campaigns. The case highlights how generative AI lowers the technical barrier for large-scale phishing operations and stress-tests provider-side content controls.

Google Gemini Prompt Injection Powers Smishing Campaign

Google Gemini Prompt Injection Powers Smishing Campaign

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.2 The Hacker News

Google has filed suit against a Chinese cybercrime network operating the Outsider phishing-as-a-service kit, which exploited Gemini AI to generate fraudulent phishing pages and power large-scale SMS phishing attacks against Americans. The network used carefully framed prompts — disguised as benign programming requests — to bypass AI safety controls and produce functional credential-harvesting websites. The case illustrates the growing industrialisation of AI-assisted phishing infrastructure, with over 1.59 million malicious URLs and 100,000 victims attributed to the operation.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.