product · 4 records
Gemini CLI

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A vulnerability in four AI coding agents allows malicious plugin code to be swapped despite version pinning.
1 outlet

Researchers warn AI coding agents are vulnerable to malicious package attacks
Researchers demonstrated that AI coding agents can be compromised by executing code from hallucinated package and repository names without verification.
1 outlet

Researchers identify sandbox escape vulnerabilities in four AI coding agents
Security researchers disclosed sandbox escape vulnerabilities in four AI coding agents—Cursor, OpenAI Codex, Google Gemini CLI, and Antigravity—by leveraging prompt injection and trusted local tool execution.
1 outlet Cyber read

Russian threat actor uses Google Gemini tool to manage dental botnet
A Russian-speaking threat actor known as 'bandcampro' utilized Google's Gemini CLI AI tool to manage a botnet of eight dental clinic computers, conducting operations such as password cracking between March and April 2026.
1 outlet