Malicious Notifications Could Trick Google Gemini Users

2026-06-03T14:51:42Z46200887ed7d59acae5e2b848a55e6208abfad572c06cdacd889247721bdd54f
API key expirationClickFixDriveSurgeFakeUpdateGitHub compromiseGlobalProtectGoogle GeminiKali365MegalodonPAN-OSPalo Altoactive exploitcloud security issues','AI agent security','agentic AI','Anthropdevice code phishingemail compromisenative Windows toolsnotificationspatch nowphishing-as-a-serviceprompt injectionsocial engineeringstock exchangesupply chaintraffic distribution systemvoice assistant

What happened

A batch of active and emerging threats reported by Dark Reading: a prompt‑injection flaw in Google Gemini's voice assistant allowed malicious commands hidden in notifications; FBI‑flagged Kali365 phishing‑as‑a‑service expanded beyond Microsoft 365 to target AWS, Okta and other platforms using device‑code phishing; DriveSurge’s TDS hijacked thousands of legitimate sites to deliver ClickFix/FakeUpdate malware; Palo Alto PAN‑OS GlobalProtect authentication‑bypass vulnerability is being actively exploited (patch immediately); the Megalodon campaign pushed thousands of malicious commits to GitHub,盗

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
46200887ed7d59acae5e2b848a55e6208abfad572c06cdacd889247721bdd54f
Enrichment time
2026-06-03T14:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.