Threat actors could compromise Google Gemini for Workspace instances with the Google Calendar invite with the new Targeted Promptware attack involving indirect prompt injection, reports Hackread.
Malicious Google Calendar invitations with concealed prompts enabled not only the theft of private emails and discovery of users' locations but also the distribution of phishing emails, creation of harmful content, and removal of calendar events, as well as the activation of users' cameras via Zoom, a study by SafeBreach researchers showed. Multiple mobile apps, including those for managing smart home devices, could also be compromised with Targeted Promptware, said researchers, who noted that almost three-quarters of Promptware threats were high-critical risks that could also affect other artificial intelligence-based systems. Google, which has been notified about the attack in February, has already implemented more robust security mechanisms and improved prompt injection attack detection systems to mitigate the threat.
AI/ML, Email security
Google Gemini for Workspace at risk of calendar invite compromise
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
