Google: state-backed hackers exploit Gemini AI for cyber recon and attacks
ID: acf00b26-a3f8-5977-bc2f-e811de48f332
STIX ID: report--acf00b26-a3f8-5977-bc2f-e811de48f332
Feed Name: Security Affairs
Google and security researchers report that nation-state and criminal actors (including UNC2970 and APT42) are weaponizing generative AI—using Gemini and other models—for target profiling, multilingual social engineering, and even on-demand code generation (HONESTCUE) that enables fileless payloads. The article also describes AI-assisted phishing kits (COINBAIT), underground services offering AI-powered tooling and jailbreaks, model-extraction attempts, and the risks from stolen API keys that can scale abuse; Google says it has detected and disrupted related activity while hardening protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
