Malicious Notifications Could Trick Google Gemini Users
2026-06-03T14:51:42Z•46200887ed7d59acae5e2b848a55e6208abfad572c06cdacd889247721bdd54f
API key expirationClickFixDriveSurgeFakeUpdateGitHub compromiseGlobalProtectGoogle GeminiKali365MegalodonPAN-OSPalo Altoactive exploitcloud security issues','AI agent security','agentic AI','Anthropdevice code phishingemail compromisenative Windows toolsnotificationspatch nowphishing-as-a-serviceprompt injectionsocial engineeringstock exchangesupply chaintraffic distribution systemvoice assistant
What happened
A batch of active and emerging threats reported by Dark Reading: a prompt‑injection flaw in Google Gemini's voice assistant allowed malicious commands hidden in notifications; FBI‑flagged Kali365 phishing‑as‑a‑service expanded beyond Microsoft 365 to target AWS, Okta and other platforms using device‑code phishing; DriveSurge’s TDS hijacked thousands of legitimate sites to deliver ClickFix/FakeUpdate malware; Palo Alto PAN‑OS GlobalProtect authentication‑bypass vulnerability is being actively exploited (patch immediately); the Megalodon campaign pushed thousands of malicious commits to GitHub,盗
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 46200887ed7d59acae5e2b848a55e6208abfad572c06cdacd889247721bdd54f
- Enrichment time
- 2026-06-03T14:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.