Automatically translated.View original post

Gemini hack found with GeminiJack

Gemini hacking has been found with GeminiJack, allowing hackers to access data on Gmail and Docs.

AI (Artificial Intelligence or Artificial Intelligence) is so useful that it has caught the eye of the whole world. Many companies have invested in its development, but many of the models available today have detected many weaknesses, many of which can harm users because they can be used by hackers.

According to a report by the website Cyber Security News, a research team from Noma Labs, an AI-based risk specialist firm, discovered a way to hack Google's Gemini AI tool on the Enterprise version (a version for large business enterprises) through a functional security vulnerability without relying on victim interaction, or Zero-Click, which the research team named the vulnerability "GeminiJack," and described the vulnerability as an architectural flaw of the system rather than a Vulnerability, according to the general understanding that the vulnerability works in terms of Prompt Injection: After the victim opens a Google Doc file, an email, or an invitation to save an appointment to a calendar (Calendar Invite) where Prompt is secretly hidden, which leads to Exfiltration of data saved on Google Workspace that the hacker wants to hacker.

The research team went on to explain that the problem is in the architecture of Google Gemini Enterprise's RAG (Retrieval-Augmented Generation) system, which is indexing, the Querries petition in the Email, Calendar events, and documents on Google Docs, to be quick to find and manage. As a result, hackers can poison AI to find sensitive information through "confidential," "API key," and "acquired" search terms on the Workspace platform. What is searched for will be displayed in Image format. Tag in the HTML language and then export it to hackers with the HTTP protocol, where the steps to perform it will contain the following 4 steps.

1. Poisoning Hackers will share documents in Docs, Email, or Calendar invitations with Prompt embedding with keywords like "Search" Sales, and the Img Tag will be displayed.

2. Trigger, because the AI Gemini has been poisoned from the previous stage. If the employee in the victim organization performs a search with a normal command like "Sales docs?" the first step will work immediately.

3.Retrieving the RAG mechanism of the Gemini body

4.Send to the hacker (Exit) The AI will retrieve everything relevant from every data source, convert it into a Tag Image to the hacker has stolen it to use.

This method is called very difficult to detect, because for employees, sending such a command is like a common command that nothing is wrong. And in the corner of the security system, it is not counted as a phishing scam. There is no malware release on the machine.

The source did not indicate what Google's opinion on the issue or whether Google has resolved the issue, so the organization running Google Gemini Enterprise may face the risk of unwitting and difficult data theft for at least a while.

# Recap 2025 # Take care of yourself # Open statements # Includes IT matters # googlegemini

2025/12/30 Edited to

... Read moreถ้าคุณใช้งาน Gemini Enterprise (โดยเฉพาะในองค์กรที่ผูกกับ Google Workspace) ประเด็น GeminiJack ทำให้ต้องกลับมาทบทวน “วิธีให้สิทธิ์ AI เข้าถึงข้อมูล” แบบจริงจังค่ะ เพราะรูปแบบนี้ไม่ได้เน้นปล่อยมัลแวร์หรือฟิชชิงตรง ๆ แต่เป็นการซ่อนคำสั่ง (prompt injection) ไว้ในเอกสาร/อีเมล/คำเชิญ Calendar แล้วรอให้ระบบ RAG ไปดึงข้อมูลที่เกี่ยวข้องขึ้นมาเอง จากที่อ่านรายงานและดูเดโม แนวคิดที่น่ากลัวคือมันอาศัยพฤติกรรมปกติในที่ทำงานมาก ๆ เช่น มีคนแชร์ Google Docs เรื่อง “Sales” หรือส่งอีเมลเกี่ยวกับดีลลูกค้า (บางเคสมีตัวเลขมูลค่าดีลระดับ 500K ด้วย) แล้วมี prompt แอบสั่งให้ Gemini “ค้นหาอีเมลฝ่ายขาย” หรือไล่หาเอกสารที่มีคำว่า confidential / API key / acquisition พอพนักงานถาม Gemini แบบคำถามทั่วไป ระบบก็อาจไปดึงข้อมูลจาก Gmail และ Docs ที่เราอนุญาตไว้ แล้วมีโอกาสถูกจัดรูปเป็น HTML (เช่น img tag) เพื่อส่งออกไปทาง HTTP ได้ ถ้าคอนฟิก/การป้องกันไม่รัดกุม สิ่งที่องค์กรพอทำได้ทันที (แบบลดความเสี่ยงก่อนรอแพตช์/อัปเดต) คือ 1) ทบทวนสิทธิ์การเข้าถึงของ Gemini Enterprise: จำกัดขอบเขตข้อมูลที่เชื่อมกับ RAG ให้ “เท่าที่จำเป็น” โดยเฉพาะการเข้าถึง Gmail/Docs ทั้งโดเมน 2) ตั้งนโยบาย Data Loss Prevention (DLP): สร้างกฎตรวจคำ/แพทเทิร์น เช่น API key, token, เลขบัตร, PII และบล็อกการแชร์/ส่งออกผิดปกติ 3) ลดการแชร์แบบกว้าง (domain-wide sharing) และใช้การแชร์เฉพาะทีม: เอกสารฝ่ายขาย/ข้อตกลงลูกค้าไม่ควรเปิดให้ค้นหาได้ทั้งองค์กร 4) อบรมพนักงานเรื่อง “prompt ที่ซ่อนอยู่”: แม้จะไม่ใช่ฟิชชิงแบบเดิม แต่ควรระวังเอกสาร/อีเมลจากภายนอกที่ชวนให้เปิดหรือกด invite แล้วมีข้อความแปลก ๆ หรือรูปแบบคำสั่งยาวผิดปกติ 5) ทำ logging/monitoring การเรียกใช้งาน Gemini และทราฟฟิกที่ผิดปกติ: ถ้ามีการเรียกดูข้อมูลจำนวนมาก หรือมีพฤติกรรมส่งออกไปโดเมนแปลก ๆ ควรมีการแจ้งเตือน ส่วนตัวมองว่าเคสนี้เป็นสัญญาณว่า “AI ที่ต่อเข้าคลังข้อมูลองค์กร” ต้องมี guardrails ระดับสถาปัตยกรรม ไม่ใช่แค่กรองคำตอบปลายทางอย่างเดียว ใครกำลัง rollout Gemini Enterprise แนะนำให้เริ่มจากกลุ่มเล็ก ๆ (pilot) และทำ threat modeling ของ workflow จริงใน Gmail/Docs/Calendar ก่อนเปิดใช้ทั้งองค์กรค่ะ