The encrypted-prompt attack that let researchers pull chat history out of Grok has also been demonstrated against Google Gemini, producing restricted content and leaking its system prompt.
The encrypted-prompt attack that let researchers pull chat history out of Grok has also been demonstrated against Google Gemini, producing restricted content and leaking its system prompt.
Researchers found that encrypted chain-of-thought blocks returned by OpenAI, Anthropic, and Google's reasoning APIs used a shared global key, letting weaker models decode stronger models' hidden reasoning and exposing 704 real privacy artifacts in published developer logs.
Between March 19 and April 21, 2026, a Russian-speaking threat actor used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure targeting a dental clinic. The AI performed 89% of the operational work. Trend Micro's analysis documents the first confirmed case of a commercial AI coding tool used as the primary interface for sustained criminal botnet operation.
Trend Micro documented a Russian-speaking threat actor who used a jailbroken Google Gemini CLI to build, operate, and migrate botnet infrastructure in real attacks. The AI performed 89% of the operational work.
Google's Mandiant M-Trends 2026 report documents the first confirmed AI-generated zero-day exploit blocked in production, adversaries achieving exploitation seven days before patches ship, and industrial-scale LLM use in offensive operations.
Google DeepMind published a 35-page AI Control Roadmap on June 18 that openly frames its own AI agents as potential insider threats, deploying structural containment controls rather than relying on alignment training alone.
Google's Threat Intelligence Group has confirmed the first known case of a nation-state actor using AI to generate a working zero-day exploit used in an active campaign. APT45 — a North Korean state-sponsored group — automated the discovery and validation of a 2FA bypass using thousands of recursive prompts. The exploit code contained forensic markers of AI generation.
SafeBreach Labs documented a prompt injection attack hiding malicious commands inside WhatsApp, Slack, or SMS notifications. Gemini treats hostile text as trusted. Patched Nov 2025.