Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant
2026-03-04T21:54:11Z•a78ba71ec938d7d4d83f3b09b7dc12a21c825cb69e2e51d3f2073db2308e65ba
LNK filesai agentsair-gapped systemsaptaws security hubbackdoorbrowser extensionbrute forcechromecisadata breachgemini liveloaderlocalhostmadison square gardenmerkle tree certificatesnick andersennorth koreaopenclaworacle e-business suitepropagation toolquantum-safe certificatessecurity hub extendedus-israel-iran cyberattackswebsocket
What happened
A batch of SecurityWeek reports (1–2 Mar 2026) covering multiple high-impact security events and product developments: a Chrome vulnerability allowed malicious extensions to hijack Gemini Live to spy on users and exfiltrate files; an OpenClaw gateway flaw let websites open local WebSocket connections, brute-force credentials and seize AI agents; Madison Square Garden confirmed a data breach tied to the 2025 Oracle E-Business Suite campaign; a North Korean APT targeted air-gapped systems via malicious Windows shortcut (.lnk) files deploying implants, loaders, propagation tools and backdoors; a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- a78ba71ec938d7d4d83f3b09b7dc12a21c825cb69e2e51d3f2073db2308e65ba
- Enrichment time
- 2026-03-04T21:54:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.