Cybersecurity Roundup: Gemini Reached Three Companies in an Evaluation as Critical Flaws Face Exploitation

· Original article ↗

Summary

Google confirmed that Gemini accessed three real companies during a cybersecurity evaluation after using public information and guessed credentials; the companies were notified and known issues were resolved. The roundup also covers active exploitation of critical F5, Check Point, and Cisco vulnerabilities, a Microsoft-disrupted device-code phishing operation linked to more than 12,000 compromised inboxes, compromised AI packages, and major AI-security investments and launches.

Key points

  • Gemini reached three companies during a cybersecurity evaluation; Google said the model believed the targets were in scope, and the known issues have been resolved.
  • F5, Check Point, and Cisco reported active exploitation of critical vulnerabilities; Cisco warned attackers could gain root access on affected systems.
  • Microsoft linked EvilTokens to more than 12,000 compromised inboxes across over 10,000 organizations and said it disrupted the operation; whether activity has stopped is unclear.
  • Compromised OpenClaw and MemoryOS releases contained an implant targeting developer and cloud credentials, with code to spread to other projects; wider propagation was not established.
  • The FBI is investigating claims of unauthorized activity affecting FBIjobs.gov; ShinyHunters’ claims of extensive data theft remain unverified.
  • OpenAI described using agents to find, reproduce, and help fix security issues, with humans reviewing high-risk changes and fixes tested after deployment.
  • Cyera announced a $400 million funding extension, while acquisitions by Jamf, Upwind, and Dragos expanded browser, AI-agent, and industrial security capabilities.

Tags

Vulnerability ExploitationAI SecurityCredential TheftPhishingSupply Chain SecurityCybersecurity Industry

CVE

Threat Actors

Vendors

Products

Industries