logo
Beware! Research shows Gmail's AI email summaries can be hacked

Beware! Research shows Gmail's AI email summaries can be hacked

Edgar Cervantes / Android Authority
TL;DR A researcher recently demonstrated a Gemini flaw that could be exploited to inject malicious instructions while using Gmail's email summary feature.
These instructions were hidden in plain text under the body of the email.
Google responded to the research, stating that it had updated its models to identify such prompt engineering measures and block phishing links.
Big tech companies have been billing AI as the ubiquitous tool that frees us from mundane activities, and that includes reading long emails thoroughly. But little do we hear about the possibility of AI unknowingly leading us into traps that may be used to steal our sensitive data. That's precisely what recent research highlighted when it discussed the possibility of hackers using Gemini as means for phishing.
Recently, a cybersecurity researcher demonstrated a vulnerability targeting Google Workspace users where Gemini can be manipulated to display malicious instructions. The vulnerability was submitted to 0din, which is the Mozilla Foundation's bug bounty program for AI applications, and talks more specifically about the ease of misguiding Gmail's email summarization feature for Google Workspace subscribers.
The submission demonstrates how deceptive prompts can be inserted into an email's body in plain HTML format or as text hidden with an invisible font color. Gemini interprets these prompts as commands and can display them in the email summary without any caution.
Since the message is hidden in the body of the original email, it goes unnoticed by the receiver, who is likely to believe it to be a warning generated by Gemini. Researcher blurrylogic pointed out that this can be exploited to display messages that may compel the recipient to share sensitive information without proper verification, which could lead to their credentials being stolen using social engineering.
Shortly after the findings were published on 0din, Google shared details about steps it had taken to make Gemini more resilient against such tactics. Addressing reports about Gemini's vulnerability, Google said it continually updates its repository of malicious prompts or instructions that can manipulate the chatbot's output. The underlying machine learning models are constantly trained to ensure they don't respond to malicious instructions.
Google
Google also listed other steps it takes to counter different forms of phishing attempts. It noted that Gemini identifies suspicious or rogue links disguised as useful ones in the email body and redacts them from the email summaries. To further strengthen its security measures, Gemini also requests confirmation for actions such as deleting specific tasks.
Despite Google's prompt measures, we should be warned that online threat perpetrators usually think one step ahead. Therefore, we advise against blindly trusting any messages in Gemini that prompt actions such as clicking a link, making a call, or emailing a specific person.
Got a tip? Talk to us! Email our staff at
Email our staff at news@androidauthority.com . You can stay anonymous or get credit for the info, it's your choice.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Meta and Google are laying a web of globe-spanning subsea cables. We found out what's involved
Meta and Google are laying a web of globe-spanning subsea cables. We found out what's involved

CNBC

time10 minutes ago

  • CNBC

Meta and Google are laying a web of globe-spanning subsea cables. We found out what's involved

U.S. hyperscalers Meta and Alphabet 's Google are rolling out a fast-growing web of transcontinental subsea cables, looking to keep pace with ever-increasing bandwidth demand and artificial intelligence workloads. Submarine cables are the backbone of the world's internet and telecommunications infrastructure, enabling everything from international phone calls to financial transactions. While satellites play a complementary role, these largely unseen data super-highways carry the vast majority of global internet traffic. By some estimates , as much of 95% of international traffic passes through fiber-optic cables across the ocean floor. Subsea cables have typically been the domain of telecom giants and state-backed consortiums. However, Silicon Valley giants such as Meta, Google, Amazon and Microsoft have taken on the mantle over the past decade. The conversations around the resilience of this global web, this sort of foundation layer of the internet … is coming more and more to the forefront. Senior director of global submarine networks at Google Nigel Bayliff A steady stream of investment has driven " tremendous growth " in submarine cable infrastructure in recent years, according to Washington, D.C. -based telecoms research firm TeleGeography, which added the trend shows no sign of slowing. "It's definitely an amazing technology," Alan Mauldin, research director at the company, told CNBC by video call. "To be able to send light through an optical fiber thousands and thousands of kilometers across the ocean floor, that's unbelievable right? And [consider] the fact that it works so well and, generally, you don't have any problem with the quality." Project Waterworth Meta recently announced plans to build the world's longest subsea cable. Known as Project Waterworth, the U.S. tech giant said the multi-billion-dollar cable system will reach five continents and span 50,000 kilometers (31,069 miles) — making it longer than the Earth's circumference. When completed, the 24 fiber-pair submarine cable is set to bring high-capacity technology to the U.S., India, Brazil and South Africa, among other key regions. Alex Aime, head of network infrastructure at Meta — which owns Facebook, Instagram and WhatsApp — said the landmark project was led by three objectives: achieving capacity, resiliency and global reach. "First, we really need to increase capacity. AI requires a few different things, it requires compute, it requires data and it requires connectivity," Aime told CNBC by video call. "And when you're talking connectivity, you're not just talking about terrestrial connectivity, in terms of data centers, but you're also talking about intercontinental connectivity." Aime said Meta has invested in about 30 cables since the early 2010s, although not all of these are currently operational. Read more Baltic Sea nations seek to limit further incidents after cable breaches Undersea cable cuts in the Baltic Sea are stoking geopolitical tensions — here's what's going on The next front in U.S.-China tech battle? Underwater cables that power the global internet On resiliency, Aime said that constrained corridors, geopolitical factors and reliability challenges were among the reasons driving the firm's push to improve the diversity of deep-sea cables. "We fundamentally believe that AI should not be something that is limited to just individuals in the U.S. but something that can benefit everyone. So, Waterworth enables us to ensure that global connectivity," Aime said. How do subsea cables work? Google, which has invested in more than 30 cables around the world, recently announced the launch of Sol subsea cable system, saying it will connect the U.S., Bermuda, the Azores and Spain. The project is designed to help meet growing customer demand for Google Cloud and AI services across the globe. "In reality, since the dawn of the data age, 99% of all data transmission between countries where they are separated by an ocean has been carried on submarine cables. It facilitates everything," Nigel Bayliff, senior director of global submarine networks at Google, told CNBC by video call. "The conversations around the resilience of this global web, this sort of foundation layer of the internet … is coming more and more to the forefront," he added. In practice, subsea cables are about the size of a garden hose and carry a package of fibers to transmit data from point A to point B. The development process of laying one can take about four years, Bayliff said, noting that this includes route selection, survey permits, manufacturing, installation permits, installation, testing, operational permits and building a cable. "It is really very straightforward and no different to how the first cables were laid in the 1850s. We put the cable into a huge ship in a reverse format and we start from one end and very slowly lay it out to the other end," Bayliff said. "After that, it's there. We power it. We test the equipment on it and, with our fingers crossed, that should be it for 20 years of solid service." Researchers at the U.K.'s Oxford Internet Institute said Meta and Google's rollout of large-scale subsea cables underscores the fact that Big Tech firms "are now large enough to have a business case for individually financing something that previously required a consortium to make economic sense." This shift may also raise questions for policymakers concerned about the growing concentration of digital infrastructure, the researchers noted in a March blog post .

BlackBerry Partners with EC-Council to Help Strengthen Malaysia's Cybersecurity Workforce
BlackBerry Partners with EC-Council to Help Strengthen Malaysia's Cybersecurity Workforce

Associated Press

time41 minutes ago

  • Associated Press

BlackBerry Partners with EC-Council to Help Strengthen Malaysia's Cybersecurity Workforce

Malaysia's Cybersecurity Center of Excellence (CCoE) expands curriculum with self-paced training for civil servants through EC-Council's advanced learning platform CYBERJAYA, MALAYSIA / ACCESS Newswire / July 16, 2025 / BlackBerry Limited (NYSE:BB)(TSX:BB) and EC-Council, a global leader in cybersecurity certifications and learning technology, today announced a new partnership that will offer government employees nationwide with increased access to cybersecurity training and certifications through the Cybersecurity Center of Excellence (CCoE) in Malaysia. The collaboration supports Malaysia's pioneering efforts to boost human cyber capital and strengthen the nation's defences against growing digital threats, equipping government employees with advanced, industry-relevant skills through flexible learning modules. In collaboration with the Malaysian Communications and Multimedia Commission (MCMC), the partnership will further expand the CCoE Cybersecurity Curriculum, which already offers a wide range of globally recognized course offerings and certifications. With the addition of the cutting-edge EC-Council Learning (ECL) platform, one of the world's most advanced cloud-based cybersecurity education ecosystems, the CCoE is expanding self-paced online and in-person learning for Malaysian civil servants, helping more men and women to upskill and complete courses in their own time. In support of the Malaysian government's commitment to cybersecurity capacity building, the addition of EC-Council Learning marks a significant evolution of the CCoE's curriculum, enhancing its existing programs with a robust, cloud-based platform to bolster government workforces with world-class skills and qualifications as cyber threats escalate. Jaclyn Sim, Cybersecurity Training Manager for BlackBerry at the Malaysia Cybersecurity Center of Excellence, said, 'BlackBerry's partnership with EC-Council represents a meaningful step forward in the shared mission to build a cyber-resilient Malaysia. This initiative builds upon the CCoE's extensive curriculum of online and in-person training, with an advanced, flexible platform that empowers civil servants to learn anytime, anywhere. Together with MCMC, we remain committed to upskilling and fostering a culture of continuous learning across the public sector.' Jay Bavisi, Founder and CEO of EC-Council added, 'At the heart of this partnership is a shared mission between EC-Council, BlackBerry and the Cybersecurity Center of Excellence to build a cyber-resilient Malaysia by placing trusted, modern cyber learning tools in the hands of every civil servant.' Through this initiative, Malaysian civil service professionals will gain access to a full spectrum of programs aligned with national digital ambitions, including: This BlackBerry and EC-Council news also coincides with the recent 12-month anniversary of the Cybersecurity Center of Excellence (CCoE), which has rapidly grown into an international hub for cyber talent development, attracting a $3.9M CAD investment from the Government of Canada. Over the past year, the CCoE has launched several initiatives, including multiple partnerships with globally-certified partners such as CompTIA, SANS Institute, ICS2 and Rogers Cybersecure Catalyst, awarded scholarships to aspiring cyber leaders and introduced programs to foster diversity and inclusion in the sector. Find out more about EC-Council courses for Malaysian civil servants at the CCoE via [email protected]. Visit here for more information about the Malaysia CCoE or follow us on Linkedin. About EC-Council The International Council of E-Commerce Consultants ( EC-Council ) is a global leader in cybersecurity education, certification, and training. Known for its flagship programs such as Certified Ethical Hacker (CEH) and Certified Chief Information Security Officer (CCISO), EC-Council serves professionals in over 145 countries and is trusted by governments, military agencies, and Fortune 500 companies worldwide. About BlackBerry BlackBerry (NYSE:BB)(TSX:BB) provides enterprises and governments the intelligent software and services that power the world around us. Based in Waterloo, Ontario, the company's high-performance foundational software enables major automakers and industrial giants alike to unlock transformative applications, drive new revenue streams and launch innovative business models, all without sacrificing safety, security, and reliability. With a deep heritage in Secure Communications, BlackBerry delivers operational resiliency with a comprehensive, highly secure, and extensively certified portfolio for mobile fortification, mission-critical communications, and critical events management. For more information, visit and follow @BlackBerry. Trademarks, including but not limited to BLACKBERRY and EMBLEM Design, are the trademarks or registered trademarks of BlackBerry Limited, and the exclusive rights to such trademarks are expressly reserved. All other trademarks are the property of their respective owners. BlackBerry is not responsible for any third-party products or services. Media Contacts: BlackBerry Media Relations +1 (519) 597-7273 [email protected] Media Contact - EC-Council Sean Lim - Senior Vice President (SVP) at EC-Council [email protected] SOURCE: BlackBerry press release

Google to host Pixel 10 launch event on August 20, Verge reports
Google to host Pixel 10 launch event on August 20, Verge reports

Business Insider

timean hour ago

  • Business Insider

Google to host Pixel 10 launch event on August 20, Verge reports

Google has set an August 20 date for its Pixel 10 launch event, having sent out invites for the event which will take place at 1:00 pm ET in New York City, The Verge's Emma Roth reports. During the event, the company intends to showcase 'the latest' on its Pixel phones, watches, buds, 'and more,' the author notes. Elevate Your Investing Strategy: Take advantage of TipRanks Premium at 50% off! Unlock powerful investing tools, advanced data, and expert analyst insights to help you invest with confidence. Make smarter investment decisions with TipRanks' Smart Investor Picks, delivered to your inbox every week.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store