Gemini CLI - Tool

Threat entity extracted from intelligence sources

Frequency
25
occurrences
First Seen
December 5, 2025
Last Seen
July 23, 2026

Gemini CLI is a tool tracked across 16 threat clusters and 25 intelligence report mentions on ThreatCluster. First observed December 5, 2025; most recent activity July 23, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Cymulate, which found — cymulate.com · July 23, 2026
  • Week of Sandbox Escapes — www.pillar.security · July 21, 2026
  • AI agents can escape sandboxes without ever breaking them — Csoonline · July 21, 2026
  • Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes — Aiweekly.Co · July 21, 2026
  • Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet — Trendmicro · July 14, 2026
  • Six Minutes to Compromise: How 'Patriot Bait' Actor Used AI to Build and Deploy a C&C Botnet — Trendmicro · July 14, 2026
  • 'The bots are alive!' Jailbroken Gemini spun up new C2 server for Russian fraudster in just 6 minutes — Theregister · July 14, 2026
  • Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet — Feeds.Trendmicro · July 14, 2026

CVSS v3.1 Breakdown