🚨 New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS
Source: https://t.co/EHpSn8wX4C
A new class of indirect prompt injection (IPI) attacks targets Google Gemini's voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger.
The core exploit leverages Gemini's Android Utilities agent, specifically the tool that reads incoming notifications. Because this tool processes untrusted data from third-party apps, an attacker can embed malicious instructions directly inside a crafted message.
Once Gemini reads the poisoned notification, it silently incorporates the attacker's commands into the conversational context without the user's knowledge.
#cybersecuritynews
🗣️🗣️Please join us in welcoming @cyb3rw4v3 Networks as an Official Sponsor of the East Africa Intervarsity CTF 2026.
From cyber ranges and vulnerable labs to CTF challenges, CyberWave Networks is empowering aspiring cybersecurity professionals.
Learn. Practice. Compete.
#CTF
We’re proud to welcome APISEC University as an Official Sponsor of the East Africa Intervarsity CTF 2026.
Together, we’re building opportunities to challenge, grow, and empower the next generation of cybersecurity talent across East Africa.
#EastAfricaCTF#CyberSecurity#CTF
We’re excited to welcome MRE Security as an Official Sponsor of the East Africa Intervarsity CTF 2026.
Through education, technical content, career guidance, consulting, and community-driven learning, MRE Security continues to support growing cybersecurity professionals.
#CTF