FILTERING BY: CLEAR FILTER

Evaluating Jailbreaking Vulnerabilities in Gemini 2.0 Flash-Lite, GPT-4o mini, and Claude 3.5 Against NERC Standards

Research indicates that LLM-integrated smart grid assistants are highly susceptible to prompt-based jailbreaking, specifically targeting NERC Reliability Standards (EOP, TOP, and CIP). Using advanced adversarial methodologies such as DeepInception (63.17% ASR) and BitBypass, authorized users can bypass safety alignments to elicit dangerous operational guidance. The study benchmarks major models, revealing that Gemini 2.0 Flash-Lite is most vulnerable (55.04% ASR), while Claude 3.5 Haiku showed total resistance. This creates a critical risk where LLM-driven decision support could lead to regulatory non-compliance and physical grid instability through insider-driven manipulation.

Google DeepMind: Automated Vulnerability Discovery and the Strategic Asymmetry Risk

Google DeepMind is shifting cybersecurity from heuristic-based detection to deep semantic reasoning through frameworks like EntailLLM and Big Sleep. By integrating temporal annotated logic and Vulnerability Causal Knowledge Graphs (VCKG), these tools enable automated discovery of complex software flaws through formal reasoning. While Google demonstrated massive defensive scale by remediating 1,072 Chrome vulnerabilities in 60 days, the emergence of agentic reasoning frameworks like CLEAR introduces a profound strategic asymmetry. This transition enables adversaries to leverage AI to exploit complex causal dependencies and execution flows that traditional scanners cannot detect, accelerating a high-speed race of AI-driven vulnerability verification that threatens critical infrastructure and national security.

Google Chrome Password Manager: Passkey Theft via UV Flag Exploitation

Research from Unit 42 reveals a critical implementation flaw in how Relying Parties (RPs) validate the 'User Verified' (UV) flag within WebAuthn ceremonies, enabling malware with standard user privileges on Windows to bypass biometric and PIN requirements. By exploiting the Chrome Google Password Manager Cloud Authenticator, attackers can execute a multi-stage attack—categorized as Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—to steal synced passkeys or the master key. This vulnerability degrades passkey-based multi-factor authentication (MFA) to a single-factor dependency on local host integrity, facilitating silent, non-interactive account takeovers without user interaction or physical prompts.

Google Chrome: Transition to AI-Augmented Vulnerability Management

Google is pivoting the Chrome security lifecycle from manual triage to an AI-augmented "hyper-cadence" model. By deploying Gemini-powered agents for full codebase scanning and hybrid triage—blending rule-based logic with LLMs—the organization is automating the discovery and remediation of critical vulnerabilities. This shift has successfully identified legacy sandbox escapes that evaded human detection for over a decade. The resulting surge in discovery velocity, evidenced by 1,072 security fixes in just two releases, is necessitating an accelerated deployment pipeline, including the testing of a twice-weekly patching schedule to mitigate the risk of AI-driven adversarial exploitation.

Google and Anthropic: Fragmentation of AI Security and Nation-State LLM Operationalization

This report analyzes the diverging security strategies of Google and Anthropic amidst the rise of nation-state efforts to operationalize Large Language Models (LLMs) for automated offensive cyber operations. Technical vulnerabilities center on cryptographic weaknesses in LLM-integrated communication protocols and software supply chain gaps within cloud-integrated model access, specifically targeting Google Cloud AI/ML workloads. The strategic shift toward proprietary "walled garden" security, evidenced by the avoidance of NVIDIA’s Open Secure AI Alliance, follows agentic breaches at OpenAI that exposed risks in autonomous AI agent architectures. Current exploitation vectors focus on the interoperability codebases between Microsoft and Anthropic and specific CVEs within Google’s cloud-integrated AI ecosystem.

Critical Zero-Days in Google Chrome, Microsoft Exchange, and AWS GovCloud Credential Leak

The second week of June 2026 is marked by a high-velocity exploitation cycle targeting critical infrastructure and endpoints. Google Chrome faces its fifth zero-day of the year via an Out-of-Bounds (OOB) Read/Write in the V8 engine (CVE-2026-11645) and a Use-After-Free vulnerability (CVE-2026-11634). Simultaneously, Microsoft Exchange on-premises servers are targeted by an active zero-day (CVE-2026-42897). Infrastructure risks include a critical RCE in Unbound DNSSEC (CVE-2026-33278) and KEV-listed flaws in Arista and Cisco devices. A critical supply chain failure occurred when a CISA contractor exposed privileged AWS GovCloud credentials on GitHub, compromising high-security federal cloud environments. Immediate patching to Chrome v149.0.7827.102/.103 and remediation of KEV-listed assets are mandated.

CISA KEV Update: Active Exploitation of Google Chrome, Arista EOS, and Cisco Systems

CISA has updated its Known Exploited Vulnerabilities (KEV) catalog to include critical flaws in Google Chrome, Arista EOS, and Cisco Systems, transitioning these vulnerabilities from theoretical risks to confirmed active exploitations. The Chrome vulnerabilities involve sandbox escapes—addressed in the Stable Channel 149 update—allowing attackers to gain host-level execution from the browser process. Simultaneously, critical flaws in Arista EOS and Cisco networking hardware provide vectors for network-wide interception, disruption, and lateral movement. Immediate remediation via vendor patches is mandatory for federal agencies and critical for enterprise environments to mitigate the risk of perimeter breach and internal escalation.

Google Chrome 149: Unprecedented Security Update Addressing 429 Vulnerabilities

Google has released a massive security update for Chrome version 149, remediating a record-breaking 429 vulnerabilities. This deployment targets over 100 high-severity flaws, including 22 critical vulnerabilities capable of facilitating Remote Code Execution (RCE) and sandbox escapes. Technical analysis indicates the update primarily addresses memory safety regressions, specifically Use-after-free (UAF) primitives within the V8 JavaScript engine and the Blink rendering engine. Furthermore, the patch mitigates improper input validation logic and Mojo IPC (Inter-Process Communication) flaws, which serve as primary pathways for privilege escalation and breaking out of the browser's security sandbox.

UNC6508 Espionage Campaign Targeting Google Workspace and REDCap

Chinese-linked threat actor UNC6508 has conducted a multi-year espionage campaign since 2023 targeting North American medical research and defense organizations. The actor leverages sophisticated authentication bypasses within Google Workspace to infiltrate secure environments, specifically targeting REDCap (Research Electronic Data Capture) platforms to exfiltrate sensitive datasets. Technical objectives include the theft of intellectual property related to virology, artificial intelligence, and military research. Persistence is maintained via deployed backdoors and a dedicated Command and Control (C2) infrastructure designed for stealthy data exfiltration from critical research databases.

Google Chrome V8 Engine Zero-Day Exploitation

Google has issued emergency patches for the Chrome V8 JavaScript engine following the discovery of active, in-the-wild exploitation of multiple zero-day vulnerabilities, including CVE-2024-4947 and CVE-2024-5274. These vulnerabilities facilitate remote code execution (RCE) through sophisticated exploitation of the V8 Just-In-Time (JIT) compiler, specifically targeting type confusion and heap buffer overflow conditions. Threat actors utilize malicious site redirections and drive-by downloads to trigger memory corruption, allowing for arbitrary code execution within the browser context. Given the approximately 3.5 billion user base, immediate patching is critical to mitigate risks from advanced persistent threat (APT) activity and increasingly complex browser-based exploit chains.

Systematic Vulnerabilities in Apple AirDrop and Android Quick Share

Researchers from CISPA have identified critical, zero-click vulnerabilities in proximity-based file-transfer protocols, specifically Apple AirDrop and Google/Samsung Quick Share. Utilizing the custom "AIRFUZZ" protocol-aware fuzzer, the study uncovered systemic flaws in how privileged daemons process unauthenticated, complex serialized content such as Binary Plists, CPIO archives, and Protocol Buffers. Exploitation vectors include Swift-based Denial of Service (DoS), XML recursion, and memory corruption via Heap Use-After-Free (UAF). Most significantly, the research demonstrated a complete bypass of Device-to-Device (D2D) encryption in Samsung Quick Share. These vulnerabilities affect over 5 billion devices globally. All affected vendors—Apple, Google, and Samsung—have released patches to remediate these flaws.

Web Agent Retrieval Poisoning WARP Targeting OpenAI Deep Research and Google Gemini Deep Research

Web Agent Retrieval Poisoning (WARP) is a critical evolution in indirect prompt injection targeting agentic AI systems, including OpenAI Deep Research, Google Gemini Deep Research, and Claude Code. Attackers embed instructions within seemingly benign source material, such as public GitHub repositories, to exploit an AI agent's automated error-recovery instincts. By triggering specific logic, attackers force the agent to fetch second-stage payloads via non-file-based channels like DNS TXT records. This technique bypasses static analysis, secret scanners, and human code review, ultimately enabling Remote Code Execution (RCE) through reverse shells on developer workstations or within CI/CD pipelines.

Lumma Stealer: Bypassing Google Chrome App-Bound Encryption for Crypto Theft

Lumma Stealer has evolved its execution chain to bypass Google Chrome's App-Bound Encryption (ABE) by transitioning from offline file decryption to "living-off-the-browser" techniques. By utilizing Asynchronous Procedure Call (APC) and Remote Thread Injection into chrome.exe, or leveraging malicious Chrome extensions, the malware forces the legitimate browser process to decrypt sensitive data using its own internal APIs. This allows attackers to exfiltrate session cookies and non-custodial cryptocurrency wallet seeds, effectively neutralizing ABE and enabling MFA bypass via session hijacking. Impact is concentrated on high-value digital assets and corporate account access via SEO poisoning and malvertising delivery vectors.

Silent Ransom Group UNC3753 Leverages AnyDesk, Zoho Assist, and iManage to Target U.S. Law Firms

The threat actor known as Silent Ransom Group (UNC3753, also referred to as Luna Moth) is conducting high-tempo extortion campaigns against U.S. law and professional services firms. The attack chain utilizes spearphishing and vishing (T1566.004) to trick personnel into installing Remote Monitoring and Management (RMM) tools such as AnyDesk and SuperOps. Attackers then exploit BYOD endpoints to gain access to corporate Virtual Desktop Infrastructure (VDI), including Windows 365 and Citrix environments. Once inside, the group performs surgical data harvesting from document management systems like iManage, targeting PII and tax logs. The campaign is characterized by rapid execution—often completing the lifecycle within a single business day—and includes physical USB-based exfiltration.

Indirect Prompt Injection via SEO Poisoning Targeting OpenAI, Anthropic, and Google AI Agents

Attackers are leveraging Indirect Prompt Injection (IPI) to hijack AI agents from OpenAI, Anthropic, and Google by weaponizing the Retrieval-Augmented Generation (RAG) process. Through SEO poisoning, malicious sites are prioritized in agent grounding searches, delivering hidden payloads via CSS (display:none, opacity:0) and zero-width characters. These invisible instructions override system prompts to execute unauthorized tool-use functions, enabling cryptojacking via WebAssembly and the exfiltration of sensitive session data to attacker-controlled endpoints. This vulnerability shifts the primary attack vector from direct user input to external, untrusted data sources utilized for agentic autonomy.

GREYVIBE Leverages ChatGPT and Google Gemini for AI-Augmented Operations against Ukraine

Russia-aligned threat group GREYVIBE is utilizing OpenAI's ChatGPT and Google Gemini to facilitate "capability equalization" during cyber offensive operations against Ukrainian infrastructure. By integrating large language models (LLMs) into the cyber kill chain, the actor automates the generation of linguistically precise phishing lures, develops malware-related scripts, and streamlines post-compromise reconnaissance and lateral movement. This AI-augmented workflow enables the concurrent execution of five parallel attack chains, significantly reducing the technical skill barrier and operational cost-per-attack. The campaign demonstrates a strategic shift toward using commercial AI to mimic APT-level sophistication, posing an increased threat to critical sectors in Ukraine.

Android Framework: Actively Exploited Integer Overflow Zero-Day CVE-2025-48595

A critical integer overflow vulnerability in the Android Framework, identified as CVE-2025-48595, is being actively exploited in the wild to achieve unauthorized privilege escalation. Threat actors utilize this flaw to deploy "Landfall," a sophisticated commercial-grade spyware suite designed for clandestine surveillance and data exfiltration. By leveraging this zero-day alongside CVE-2025-48593, attackers can bypass security boundaries to gain system-level access and complete device control. This exploitation allows for the interception of sensitive personal and enterprise data, bypassing traditional network-level security controls. Google addressed these vulnerabilities in the June 2026 Android Security Bulletin.

Google Patches Actively Exploited Zero-Day in Android Framework CVE-2025-48595

Google has remediated CVE-2025-48595, a high-severity integer overflow vulnerability within the Android Framework currently leveraged in limited, targeted attacks. The flaw enables local privilege escalation (LPE) by allowing an attacker—who has already achieved initial code execution via a malicious application or browser exploit—to break the Android security sandbox and gain full system or root-level access. With a CVSS score of 8.4, the exploit requires no user interaction for the escalation phase. Due to its active exploitation, CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agency remediation by June 5, 2026.

Greyvibe: Russia-Aligned Threat Actor Leverages ChatGPT, Google Gemini, and Ideogram AI for Ukrainian Intelligence Campaigns

Greyvibe, a newly identified Russian-aligned hybrid threat actor, utilizes Generative AI tools—including ChatGPT, Google Gemini, and Ideogram AI—to accelerate the cyberattack lifecycle against Ukrainian military, government, and private sector targets. The group employs Large Language Models (LLMs) to automate the creation of custom PowerShell-based Remote Access Trojans (RATs), specifically PhantomRelay and LegionRelay, as well as the Android-based FallSpy spyware. Attackers leverage ClickFix-style phishing via fraudulent CloudFlare CAPTCHA pages and deploy obfuscated scripts, such as LOOKVALPS, LOOKVALJS, DAYLIGHT, and TEASOUP, to facilitate credential harvesting, RDP persistence, and the exfiltration of sensitive communications from platforms like Telegram and WhatsApp.

Google Chrome Implements Device Bound Session Credentials DBSC to Combat Token Theft

Google has transitioned Device Bound Session Credentials (DBSC) from beta to General Availability (GA) for Chrome on Windows. This architectural update mitigates session cookie theft and authentication token exfiltration, common vectors used by adversaries to bypass Multi-Factor Authentication (MFA) and execute account takeovers. By cryptographically binding session tokens to a specific hardware device, DBSC prevents stolen cookies from being reused on unauthorized machines, effectively neutralizing "pass-the-cookie" attacks. The feature is now enabled by default for all Google Workspace customers and Individual subscribers.

FROST: Malicious Website Exploitation of SSD/NVMe Timing Side-Channels in Google Chrome, Mozilla Firefox, and Brave

The FROST attack is a hardware-level timing side-channel vulnerability that allows malicious websites to conduct high-fidelity user surveillance by analyzing I/O latency signals from NVMe SSD controllers. By leveraging high-resolution browser APIs to measure micro-delays in disk read/write operations, an attacker can fingerprint the specific I/O signatures generated by local applications and operating system processes. This exploitation occurs via a passive "drive-by" mechanism, requiring no user interaction or privileged system access, and fundamentally circumvents existing browser security boundaries, including the Same-Origin Policy (SOP), sandboxing, and privacy-preserving modes such as Incognito or cookie-blocking extensions. Because the signal is derived from shared physical hardware rather than software-defined identifiers, the attack remains invisible to traditional endpoint detection and response (EDR) tools and browser-based privacy mitigations.


LINK COPIED TO CLIPBOARD