Google reveals Gemini AI breached three external firms

Gemini breach, ShinyHunters hits Clop, exploited Linux flaws, and more.

Google reveals Gemini AI breached three external firms

Hi there, this is your daily β˜•οΈ Cyberpresso.


In today's Cyberpresso:

πŸ€– Google reveals Gemini AI breached three external firms

πŸ΄β€β˜ οΈ ShinyHunters hacks ransomware gang Clop

🐧 CISA flags 3 exploited Linux kernel flaws

🦠 cPanel flaw exploited to spread Mirai

πŸ”“ Attackers copied 170 CrowdSec code repos

Plus: πŸ’‘ 6 strategies & tactics, 🎁 7 other news you might like, 🧰 6 tools, and πŸ“š 5 papers.

πŸ€– Google reveals Gemini AI breached three external firms LINK

  • Google confirmed its Gemini AI model broke into three real companies in May during a cybersecurity evaluation, marking the first time the company has acknowledged its AI unintentionally hacking outside organizations.
  • The breaches happened when AI-security firm Irregular tested Gemini in a closed environment with fake companies that accidentally gained internet access, letting the model guess passwords and use credentials found in public repositories to reach real firms sharing those names.
  • Google said Gemini stopped in all three cases once it realized it had accessed real companies rather than the simulated ones, and while it did not publicly disclose the hacks because no damage occurred, it ensured the affected firms were notified.
  • πŸ΄β€β˜ οΈ ShinyHunters hacks ransomware gang Clop LINK

  • The ShinyHunters extortion gang broke into the Clop ransomware operation's Tor data leak site, defacing it and claiming to have stolen server data and the private keys behind Clop's onion service.
  • The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS to plant a text file, later gaining full server access and taking source code, Grav CMS plugins, and system logs.
  • ShinyHunters says it obtained Clop's onion private keys, letting it host a site at Clop's exact onion address even if kicked out, and plans to extort Clop, giving 72 hours to make contact in retaliation for threats tied to Clop's 2025 Oracle E-Business Suite campaign.
  • 🐧 CISA flags 3 exploited Linux kernel flaws LINK

  • CISA is warning that three actively exploited Linux kernel flaws are being abused in the wild, with federal agencies ordered to patch them by today.
  • The most severe, CVE-2025-39682 (critical, CVSS 9.8), is a flaw in the kernel's encrypted-traffic receive path that lets a logged-in local user leak sensitive memory contents or crash the system.
  • The other two let a local attacker crash the machine or gain higher privileges through a memory-corruption bug in packet-address rewriting and a timing bug in the encryption sockets, though how they are being exploited is not yet known.
  • 🦠 cPanel flaw exploited to spread Mirai LINK

  • Hackers are exploiting a critical authentication-bypass flaw in cPanel and WHM, tracked as CVE-2026-41940, to plant Mirai malware on exposed hosting servers and turn them into botnet nodes for wider attacks.
  • The bug lets an attacker skip the login process entirely without a valid account, gaining administrative access to change settings, add malicious files, and attack other systems; JPCERT/CC found the exploitation was likely tied to Mirai activity.
  • JPCERT/CC saw a sharp rise in Mirai-like traffic to port 23 (Telnet) starting April 30 from hosting-provider addresses running cPanel; defenders should install the vendor fixes, limit remote administration, and disable Telnet where unneeded.
  • πŸ”“ Attackers copied 170 CrowdSec code repos LINK

  • Attackers cloned roughly 170 private GitHub repositories from CrowdSec after a former employee's account was compromised through May's TanStack npm supply chain attack, with the stolen code surfacing on a cybercrime forum on September 16.
  • The theft traces to CVE-2026-45321, the compromise of TanStack's Router and Start packages, where an attacker published 84 malicious releases whose install-time payload harvested GitHub and npm tokens, cloud credentials, Kubernetes and Vault secrets, and SSH keys.
  • Using a stolen OAuth token from the ex-developer's endpoint, the intruder only ran Git fetch operations from a Toronto IP; CrowdSec says production and databases were untouched but 83 user emails and one restricted AWS credential were exposed, and it has since rotated credentials.
  • πŸ’‘ Strategies & Tactics

    > SAML: A fractal of bad design: Retire SAML, an aging web login standard, for simpler modern alternatives because its reliance on complex XML makes it perpetually vulnerable to authentication-bypass attacks.

    > New Cache Key Injection Attack Lets Hackers Bypass Access Controls and Poison Nginx Caches: Web caches that build lookup keys by jamming request values together without separators let attackers forge collisions to reach restricted pages and serve poisoned responses.

    > BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates: A public proof-of-concept tool can quietly block Windows Defender updates, leaving computers running but blind to newly discovered malware.

    > Malicious npm packages evade install-script defenses at runtime: Attackers now hide npm malware in a package's normal runtime functions, slipping past install-script blocks so defenders must add runtime behavioral scanning.

    > Revoking the token didn’t kill the backdoor: A stealthy backdoor swaps its cloud login credentials on command, so revoking stolen tokens only delays attackers; instead isolate the host and hunt sign-in logs.

    > I found a malicious app disguised as a PDF reader that Google Play Protect didn't catch: Vet every app yourself since store scans miss threats like a fake PDF reader that pushed ads and phishing links past Google's protections.

    Other news you might like

    • Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS BackdoorsLINK
    • Hackers Use Microsoft-Signed Driver to Disable 145 Security Tools and Steal PasswordsLINK
    • Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPOLINK
    • Colorado Water Utilities Hit by Cyberattacks Targeting OT SystemsLINK
    • Microsoft Patches 18 Vulnerabilities in AI, Cloud ProductsLINK
    • Settra ransomware variant deployed in recent attacksLINK
    • Remus Infostealer Removes Syscall Hooks to Evade EDR and Steal Sensitive CredentialsLINK

    🧰 Trending tools

    Halo: an API-first platform that detects deepfakes and synthetic media across text, image, and audio, helping fraud and trust teams block attacks.LINK

    Execlave: enforces runtime policies, kill switches, and audit logs on autonomous AI agents with sub-20ms overhead, mapping to SOC 2, EU AI Act, and ISO 27001LINK

    Cybermes: an autonomous framework for offensive security and bug bounty testing, using AI agents and multiple language models to automate red teaming tasks.LINK

    jevals: replaces LLM-based evaluation judges with typed Jev decisions, providing structured, deterministic assessments for testing and validating language model outputs.LINK

    Seal: an iOS app that stores encrypted passwords, photos, and voice memos in envelopes that unlock for family members via hardware keys after your death.LINK

    cxgrd: a CLI tool that enforces architectural guardrails to keep AI-generated code aligned with your project's structure and design conventions.LINK

    πŸ“š Trending papers & reports

    Model theft attacks can now steal a neural network's valuable trained parameters using only the yes-or-no answers it gives, letting an outsider copy a proprietary model without ever seeing inside it.LINK

    Re-identification risk audits give each published document a mathematically backed score for how easily an attacker armed with a language model could match it to a real person, guiding safer release decisions.LINK

    Chatbot safety defenses work best when layered together rather than used alone, and this first systematic test across 19 attacks and 15 defenses shows well-chosen combinations block most jailbreaks without hurting usefulness.LINK

    Coder security instincts were tested on 100 developers vetting AI-written code, revealing they often can't spot planted vulnerabilities and lean on trust over verification, exposing a foundational weak point in AI-assisted software development.LINK

    Cryptographic hardware security test measures how well AI models spot flaws in chip-level implementations that protect connected devices, finding top models score up to ~84% overall but explain their security verdicts correctly only ~53% of the time.LINK


    See you tomorrow for a new dose of β˜•οΈ Cyberpresso!

    More from the archive