{"id":185429,"date":"2025-12-10T20:32:07","date_gmt":"2025-12-10T20:32:07","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/185429\/"},"modified":"2025-12-10T20:32:07","modified_gmt":"2025-12-10T20:32:07","slug":"geminijack-exploit-exposes-gmail-docs-and-calendars-to-silent-ai-attacks","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/185429\/","title":{"rendered":"GeminiJack Exploit Exposes Gmail, Docs, and Calendars to Silent AI Attacks"},"content":{"rendered":"<p>\t\t\t\t\t .elementor-widget-container{margin:0px 0px 0px 0px;padding:0px 0px 0px 0px;}.elementor-65851 .elementor-element.elementor-element-1cf67f8.elementor-element{&#8211;flex-grow:0;&#8211;flex-shrink:0;}.elementor-65851 .elementor-element.elementor-element-fba5b18{&#8211;display:flex;&#8211;flex-direction:row;&#8211;container-widget-width:initial;&#8211;container-widget-height:100%;&#8211;container-widget-flex-grow:1;&#8211;container-widget-align-self:stretch;&#8211;flex-wrap-mobile:wrap;}.elementor-widget-form .elementor-field-group > label, .elementor-widget-form .elementor-field-subgroup label{color:var( &#8211;e-global-color-text );}.elementor-widget-form .elementor-field-type-html{color:var( &#8211;e-global-color-text );}.elementor-widget-form .elementor-field-group .elementor-field{color:var( &#8211;e-global-color-text );}.elementor-widget-form .e-form__buttons__wrapper__button-next{background-color:var( &#8211;e-global-color-accent );}.elementor-widget-form .elementor-button[type=&#8221;submit&#8221;]{background-color:var( &#8211;e-global-color-accent );}.elementor-widget-form .e-form__buttons__wrapper__button-previous{background-color:var( &#8211;e-global-color-accent );}.elementor-widget-form{&#8211;e-form-steps-indicator-inactive-primary-color:var( &#8211;e-global-color-text );&#8211;e-form-steps-indicator-active-primary-color:var( &#8211;e-global-color-accent );&#8211;e-form-steps-indicator-completed-primary-color:var( &#8211;e-global-color-accent );&#8211;e-form-steps-indicator-progress-color:var( &#8211;e-global-color-accent );&#8211;e-form-steps-indicator-progress-background-color:var( &#8211;e-global-color-text );&#8211;e-form-steps-indicator-progress-meter-color:var( &#8211;e-global-color-text );}.elementor-65851 .elementor-element.elementor-element-5169176{width:var( &#8211;container-widget-width, 98.54% );max-width:98.54%;&#8211;container-widget-width:98.54%;&#8211;container-widget-flex-grow:0;&#8211;e-form-steps-indicators-spacing:17px;&#8211;e-form-steps-indicator-padding:30px;&#8211;e-form-steps-indicator-inactive-secondary-color:#ffffff;&#8211;e-form-steps-indicator-active-primary-color:var( &#8211;e-global-color-secondary );&#8211;e-form-steps-indicator-active-secondary-color:#ffffff;&#8211;e-form-steps-indicator-completed-secondary-color:#ffffff;&#8211;e-form-steps-divider-width:2px;&#8211;e-form-steps-divider-gap:10px;}.elementor-65851 .elementor-element.elementor-element-5169176 > .elementor-widget-container{margin:0px 0px 0px 0px;padding:0px 0px 0px 0px;}.elementor-65851 .elementor-element.elementor-element-5169176.elementor-element{&#8211;align-self:center;&#8211;flex-grow:0;&#8211;flex-shrink:0;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-field-group{padding-right:calc( 60px\/2 );padding-left:calc( 60px\/2 );margin-bottom:20px;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-form-fields-wrapper{margin-left:calc( -60px\/2 );margin-right:calc( -60px\/2 );margin-bottom:-20px;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-field-group.recaptcha_v3-bottomleft, .elementor-65851 .elementor-element.elementor-element-5169176 .elementor-field-group.recaptcha_v3-bottomright{margin-bottom:0;}body.rtl .elementor-65851 .elementor-element.elementor-element-5169176 .elementor-labels-inline .elementor-field-group > label{padding-left:0px;}body:not(.rtl) .elementor-65851 .elementor-element.elementor-element-5169176 .elementor-labels-inline .elementor-field-group > label{padding-right:0px;}body .elementor-65851 .elementor-element.elementor-element-5169176 .elementor-labels-above .elementor-field-group > label{padding-bottom:0px;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-field-type-html{padding-bottom:0px;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-field-group .elementor-field:not(.elementor-select-wrapper){background-color:#ffffff;border-width:1px 1px 1px 1px;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-field-group .elementor-select-wrapper select{background-color:#ffffff;border-width:1px 1px 1px 1px;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-button{font-size:16px;font-weight:400;line-height:14px;letter-spacing:1px;border-radius:5px 5px 5px 5px;}.elementor-65851 .elementor-element.elementor-element-5169176 .e-form__buttons__wrapper__button-next{background-color:#000000;color:#ffffff;transition-duration:600ms;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-button[type=&#8221;submit&#8221;]{background-color:#000000;color:#ffffff;transition-duration:600ms;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-button[type=&#8221;submit&#8221;] svg *{fill:#ffffff;transition-duration:600ms;}.elementor-65851 .elementor-element.elementor-element-5169176 .e-form__buttons__wrapper__button-previous{background-color:#000000;color:#ffffff;transition-duration:600ms;}.elementor-65851 .elementor-element.elementor-element-5169176 .e-form__buttons__wrapper__button-next:hover{background-color:var( &#8211;e-global-color-9cda7ec );color:#ffffff;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-button[type=&#8221;submit&#8221;]:hover{background-color:var( &#8211;e-global-color-9cda7ec );color:#ffffff;}.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-button[type=&#8221;submit&#8221;]:hover svg *{fill:#ffffff;}.elementor-65851 .elementor-element.elementor-element-5169176 .e-form__buttons__wrapper__button-previous:hover{color:#ffffff;}@media(max-width:1024px){.elementor-65851 .elementor-element.elementor-element-fba5b18{&#8211;min-height:100px;&#8211;flex-direction:column;&#8211;container-widget-width:calc( ( 1 &#8211; var( &#8211;container-widget-flex-grow ) ) * 100% );&#8211;container-widget-height:initial;&#8211;container-widget-flex-grow:0;&#8211;container-widget-align-self:initial;&#8211;flex-wrap-mobile:wrap;&#8211;justify-content:space-between;&#8211;align-items:center;&#8211;flex-wrap:wrap;}}@media(max-width:767px){.elementor-65851 .elementor-element.elementor-element-89c0dd0{&#8211;flex-wrap:wrap;}.elementor-65851 .elementor-element.elementor-element-5169176.elementor-element{&#8211;flex-grow:1;&#8211;flex-shrink:0;}}@media(min-width:768px){.elementor-65851 .elementor-element.elementor-element-89c0dd0{&#8211;width:90%;}.elementor-65851 .elementor-element.elementor-element-fca7fb2{&#8211;width:58.509%;}.elementor-65851 .elementor-element.elementor-element-fba5b18{&#8211;width:74%;}}@media(max-width:1024px) and (min-width:768px){.elementor-65851 .elementor-element.elementor-element-fca7fb2{&#8211;width:288.502px;}.elementor-65851 .elementor-element.elementor-element-fba5b18{&#8211;width:500px;}}\/* Start custom CSS for form, class: .elementor-element-5169176 *\/.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-field-group {<br \/>\n  width: 100%;<br \/>\n}<\/p>\n<p>.elementor-65851 .elementor-element.elementor-element-5169176 .elementor-button {<br \/>\n  width: 100%;<br \/>\n  display: block;<br \/>\n}\/* End custom CSS *\/]]><\/p>\n<p>A newly disclosed vulnerability in Google\u2019s Gemini Enterprise allowed attackers to extract private corporate data without requiring any interaction from the user. <\/p>\n<p>The issue, discovered by researchers at Noma Security and named GeminiJack, took advantage of how Gemini handled shared content when performing AI-powered searches. Instead of relying on malware or phishing, the attack used carefully placed prompt injections inside documents, calendar invites, and emails.<\/p>\n<p>Once <a href=\"https:\/\/nationalcioreview.com\/articles-insights\/extra-bytes\/new-cloud-forecast-oracle-with-a-chance-of-gemini\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Gemini<\/a> indexed the shared content, it treated the hidden prompt like part of its normal instructions. <\/p>\n<p>Later, when an employee searched for something like \u201ccustomer invoices\u201d or \u201csales targets,\u201d the AI followed the attacker\u2019s command. It pulled sensitive data and placed it inside an image link that sent the information to the attacker\u2019s server.<\/p>\n<p>To the employee, the search result looked normal, and no security systems flagged the activity.<\/p>\n<p>Why It Matters: This exploit introduced a threat that relied entirely on shared content to cause a breach. Users didn\u2019t need to click links or open files, and security tools stayed silent. The AI operated through approved systems and behaved as expected, which allowed the data to be taken without detection. The problem came from how the <a href=\"https:\/\/nationalcioreview.com\/articles-insights\/extra-bytes\/claude-at-the-center-of-the-first-documented-ai-driven-cyberattack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">AI<\/a> interpreted and acted on the content it was given.<\/p>\n<p><a data-no-instant=\"1\" href=\"https:\/\/nationalcioreview.com\/sign-up\/\" rel=\"noopener nofollow\" class=\"a2t-link\" target=\"_blank\" aria-label=\"Write for TNCR and expand your brand to over 40,000 subscribers (14)\"><img fetchpriority=\"high\" decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2025\/12\/Write-for-TNCR-and-expand-your-brand-to-over-40000-subscribers-14.png\" alt=\"\"   width=\"2048\" height=\"253\"\/><\/a><\/p>\n<p>Prompt Injection Used Shared Workspace Content: Attackers embedded hidden instructions inside Google Docs, <a href=\"https:\/\/nationalcioreview.com\/articles-insights\/extra-bytes\/calendly-emails-impersonate-major-brands-in-new-credential-theft-scheme\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Calendar events<\/a>, and Gmail messages. Once these items were shared and indexed, the AI treated them as part of the search environment. The prompts instructed Gemini to look for certain terms, such as \u201cconfidential\u201d or \u201cinternal report,\u201d and include the results inside an HTML image tag.<\/p>\n<p>Trigger Came From Routine AI Use: Employees didn\u2019t need to take any special action. A simple AI query, like \u201cshow latest contracts,\u201d was enough to activate the attack. Gemini included the attacker\u2019s prompt in the search context, followed the instructions, and placed the results into a request for an image. The image URL pointed to the attacker\u2019s server.<\/p>\n<p>No Alerts or Warnings Were Triggered: The final response included an image that the user\u2019s browser attempted to load. Because the image request looked harmless, it passed through security filters without inspection. Antivirus tools and DLP systems saw nothing out of the ordinary. From the user\u2019s perspective, the AI worked as intended.<\/p>\n<p>RAG Design Increased Exposure: Gemini\u2019s Retrieval-Augmented Generation system pulls information from Gmail, Calendar, and Docs to improve search results. This same system made it possible for malicious prompts to influence the AI\u2019s behavior. Once a shared file was indexed, it could affect future searches across the organization, including content far beyond the original source.<\/p>\n<p>Google Made Structural Changes to Mitigate the Flaw: After reviewing the report from Noma Security, Google updated how Gemini processes retrieved content. Vertex AI Search was separated from Gemini, and new limits were introduced to reduce the influence of prompt-like text within indexed materials. These changes were designed to prevent similar attacks from using shared content to affect AI behavior.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/gemini-zero-click-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Go Deeper -&gt; Gemini Zero-Click Vulnerability Let Attackers Access Gmail, Calendar, and Docs \u2013 Cyber Security News<\/a><\/p>\n<p><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/google-fixes-gemini-enterprise-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google Fixes Zero Click Gemini Enterprise Flaw That Exposed Corporate Data \u2013 Infosecurity Magazine<\/a><\/p>\n<p>\n\t\t\t\t\tTrusted insights for technology leaders\t\t\t\t<\/p>\n<p data-start=\"116\" data-end=\"355\">Our readers are CIOs, CTOs, and senior IT executives who rely on The National CIO Review for smart, curated takes on the trends shaping the enterprise, from GenAI to cybersecurity and beyond.<\/p>\n<p data-start=\"357\" data-end=\"490\">Subscribe to our 4x a week newsletter to keep up with the insights that matter.<\/p>\n","protected":false},"excerpt":{"rendered":".elementor-widget-container{margin:0px 0px 0px 0px;padding:0px 0px 0px 0px;}.elementor-65851 .elementor-element.elementor-element-1cf67f8.elementor-element{&#8211;flex-grow:0;&#8211;flex-shrink:0;}.elementor-65851 .elementor-element.elementor-element-fba5b18{&#8211;display:flex;&#8211;flex-direction:row;&#8211;container-widget-width:initial;&#8211;container-widget-height:100%;&#8211;container-widget-flex-grow:1;&#8211;container-widget-align-self:stretch;&#8211;flex-wrap-mobile:wrap;}.elementor-widget-form .elementor-field-group > label, .elementor-widget-form .elementor-field-subgroup label{color:var( &#8211;e-global-color-text );}.elementor-widget-form .elementor-field-type-html{color:var(&hellip;\n","protected":false},"author":2,"featured_media":185430,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[914,61,60,80],"class_list":["post-185429","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-front-page","tag-ie","tag-ireland","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/185429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=185429"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/185429\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/185430"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=185429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=185429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=185429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}