
Gemini CLI Exploited: Data Exfiltration in 48 Hours
Researchers exploited Google's new Gemini CLI coding agent within 48 hours of its release. By manipulating a README.md file with a prompt injection, they bypassed security controls and exfiltrated data to a remote server. The attack leveraged a benign-looking code package, highlighting the vulnerability of AI tools to prompt...








