Google Calendar invites let researchers hijack Gemini to leak user data (www.bleepingcomputer.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 11 Aug 12:17
https://sh.itjust.works/post/43868048

#cybersecurity

threaded - newest

RoadTrain@lemdro.id on 11 Aug 12:43 collapse

To clarify, this would only have been triggered if you asked Gemini to parse your calendar events:

Once the victim interacts with Gemini, like asking “What are my calendar events today,” Gemini pulls the list of events from Calendar, including the malicious event title the attacker embedded.

Is asking the bot to read your calendar events and “summarize” them really an improvement over just looking at the calendar yourself?

thisbenzingring@lemmy.sdf.org on 11 Aug 13:43 collapse

so have you read that bit about how the CEO of Microsoft uses AI?

i suspect this attack is aimed at a similar audience, executive suite level idiots who don’t know how to use technology