Gemini CLI is a tool tracked across 16 threat clusters and 25 intelligence report mentions on ThreatCluster. First observed December 5, 2025; most recent activity July 23, 2026.
A critical vulnerability in Google’s Gemini CLI, tracked as CVE-2026-12537, has been disclosed, enabling attackers to execute arbitrary code in CI/CD environments, particularly within GitHub Actions workflows. This flaw…
Google has issued urgent security updates for its Gemini CLI and GitHub Action to address a critical vulnerability, identified as GHSA-wpqr-6v78-jr5g. This flaw allows for Remote Code Execution (RCE) attacks due to…
Cato AI Labs disclosed two critical remote code execution (RCE) vulnerabilities in Cursor IDE, tracked as CVE-2026-50548 and CVE-2026-50549. These vulnerabilities allow attackers to exploit zero-click prompt injection,…
A Russian-speaking threat actor known as 'bandcampro' utilized AI to migrate a command-and-control (C&C) botnet in just six minutes, performing only 11% of the work manually. The operation targeted eight computers in a…
A report by OX Security has identified a critical vulnerability in the Model Context Protocol (MCP) developed by Anthropic, potentially exposing over 200,000 AI servers to remote code execution. The flaw lies in the…
The InstallFix campaign targets users by creating fake installation pages for Anthropic's Claude AI, tricking them into executing malware. This sophisticated social engineering tactic exploits the growing reliance on AI…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
A targeted campaign exploiting GitHub Actions' pull_request_target trigger was identified, allowing attackers to execute malicious code with elevated privileges. This vulnerability has been documented since 2021 but…
A vulnerability in AWS Kiro, an AI-powered IDE, was disclosed on July 21, 2026, allowing attackers to execute code on a developer's machine through a hidden line of text on a webpage. The flaw bypasses Kiro's…
Researchers from the ASSET Research Group demonstrated a new attack method called 'Ghostcommit' that hides malicious instructions within PNG images to bypass AI code reviewers. The attack exploits a significant gap in…