Close Menu
  • Home
  • Lifestyle
  • Tech
  • Travel
  • Review
  • About
  • Contact
What's Hot

MGEN Energy Capacity Mix Supports PH Power Future

May 6, 2026

Kaspersky Study: 85% of Parents Say They Can Protect Their Kids Online, But “Sharenting” Says Otherwise

May 6, 2026

foodpanda offers Mother’s Day deals for every kind of “kahit ano”

May 6, 2026
Facebook X (Twitter) Instagram
Manila Republic
  • Home
  • Lifestyle
  • Tech
  • Travel
  • Review
  • About
  • Contact
Manila Republic
Home»Tech»Tenable Exposes AI Flaws in Google Gemini Through Gemini Trifecta
Tech

Tenable Exposes AI Flaws in Google Gemini Through Gemini Trifecta

GabrielBy GabrielOctober 1, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Gemini Trifecta exposes AI flaws in Google Gemini

Tenable has uncovered critical vulnerabilities in Google’s Gemini suite, calling them the Gemini Trifecta. These flaws, now fixed, showed how attackers could exploit Gemini itself to steal sensitive data from millions of users.

The Gemini Trifecta impacted three core features of the platform. In Gemini Cloud Assist, attackers could plant poisoned log entries that triggered hidden malicious instructions. In the Gemini Search Personalization Model, queries could be injected into a victim’s browser history, giving attackers access to location details and saved user memories. In the Gemini Browsing Tool, Gemini could be tricked into making hidden outbound requests that leaked private data to attacker-controlled servers.

These flaws revealed how Gemini could shift from being a target to becoming an active attack vehicle. Unlike traditional cyberattacks, no malware or phishing was needed. Gemini’s trusted integrations became the attack surface.

According to Tenable Research, the problem stemmed from Gemini failing to distinguish safe user input from attacker-supplied content. Poisoned logs, search history entries, or hidden web content were all treated as trusted context.

Liv Matan, Senior Security Researcher at Tenable, explained that the flaws show the unique risks of AI platforms. “Gemini draws its strength from pulling context across logs, searches, and browsing. That same capability can become a liability if attackers poison those inputs.”

The potential impact was significant. Attackers could have silently manipulated logs, stolen sensitive user data, abused cloud resources, and redirected private data to malicious servers.

Google has remediated all three vulnerabilities. No user action is required, but Tenable urges security teams to take proactive steps:

  • Treat AI-driven features as active attack surfaces.
  • Audit logs, search histories, and integrations regularly.
  • Monitor for unusual tool executions and outbound requests.
  • Test AI-enabled services against prompt injection attacks.

Matan emphasized that this is a wake-up call. “Securing AI isn’t just about patching flaws. It’s about anticipating how attackers could exploit the unique mechanics of AI systems and building layered defenses that prevent small cracks from becoming systemic exposures.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Gabriel
  • Facebook
  • X (Twitter)

Introvert, wanderer, blogger, foodie, a hip-hop music writer, and one of the co-founders of a tech start-up company called GigsManila.

Related Posts

Keeper Security Launches Agent Kit to Secure AI-Driven Developer Workflows

April 30, 2026

QEMU abused to evade detection and enable ransomware delivery

April 29, 2026

Ant International Launches Open-Sourced Agentic Mobile Protocol to Drive AI Commerce

April 29, 2026
Leave A Reply Cancel Reply

Advertisement
Top Posts

MGEN Energy Capacity Mix Supports PH Power Future

May 6, 2026

Kaspersky Study: 85% of Parents Say They Can Protect Their Kids Online, But “Sharenting” Says Otherwise

May 6, 2026

foodpanda offers Mother’s Day deals for every kind of “kahit ano”

May 6, 2026

foodpanda PH wins multiple honors at the 2026 Asia-Pacific Stevie Awards

May 6, 2026

DaVinci Gourmet Names Winner of Asia Pacific Barista Craft Championship Regionals 2025–26 

May 6, 2026
Advertisement
Don't Miss

MGEN Energy Capacity Mix Supports PH Power Future

GabrielMay 6, 2026

Power use continues to shape daily life in the Philippines. Homes need stable electricity. Businesses…

Kaspersky Study: 85% of Parents Say They Can Protect Their Kids Online, But “Sharenting” Says Otherwise

May 6, 2026

foodpanda offers Mother’s Day deals for every kind of “kahit ano”

May 6, 2026

foodpanda PH wins multiple honors at the 2026 Asia-Pacific Stevie Awards

May 6, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
© 2026 ThemeSphere. Designed by ThemeSphere.
  • Home
  • Lifestyle
  • Tech
  • Travel
  • Review
  • About
  • Contact

Type above and press Enter to search. Press Esc to cancel.