<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Gcp on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/gcp/</link><description>Recent content in Gcp on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 19:11:15 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/gcp/index.xml" rel="self" type="application/rss+xml"/><item><title>Google Gemini Android Hijack via Notification Prompt Injecti</title><link>https://zxcloudsecurity.co.uk/posts/google-gemini-android-prompt-injection-notification-hijack/</link><pubDate>Wed, 03 Jun 2026 19:11:15 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/google-gemini-android-prompt-injection-notification-hijack/</guid><description>A prompt injection flaw let malicious WhatsApp, Slack, or SMS notifications hijack Google Gemini on Android — no malware required. Here&amp;#39;s what architects n</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html">The Hacker News</a></p>
<hr>
<p>A vulnerability in Google Gemini&rsquo;s Android integration allowed malicious content embedded in notifications from apps such as WhatsApp, Slack, Signal, and SMS to hijack the AI assistant without requiring any installed malware. An attacker could craft a poisoned notification that caused Gemini to open browser windows, impersonate contacts, initiate calls, or corrupt the assistant&rsquo;s long-term memory. This is a prompt injection attack exploiting the trust Gemini places in notification content it processes.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Organisations deploying Android devices with Gemini enabled should review mobile device management (MDM) policies to restrict AI assistant access to sensitive notification streams, and treat AI assistants as untrusted data processors when designing data-handling workflows. Raise awareness with security teams about prompt injection as a realistic attack vector on enterprise mobile estates.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html">WhatsApp, Slack Notifications Could Hijack Google Gemini on Android</a></p>
]]></content:encoded></item><item><title>Google Gemini Android Prompt Injection via Notifications</title><link>https://zxcloudsecurity.co.uk/posts/google-gemini-android-prompt-injection-whatsapp-slack-notifications/</link><pubDate>Wed, 03 Jun 2026 19:11:15 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/google-gemini-android-prompt-injection-whatsapp-slack-notifications/</guid><description>A prompt injection flaw let hostile WhatsApp, Slack, and Signal notifications hijack Google Gemini on Android — no malicious app required.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html">The Hacker News</a></p>
<hr>
<p>A prompt injection vulnerability in Google Gemini on Android allowed hostile content embedded in notifications from apps such as WhatsApp, Slack, Signal, and SMS to hijack the AI assistant without requiring any malicious app to be installed. An attacker could craft a poisoned message or notification that caused Gemini to perform unauthorised actions — including impersonating contacts, initiating calls, or corrupting its long-term memory. The attack required no user interaction beyond the assistant processing the notification, making it particularly dangerous for enterprise users relying on AI-assisted workflows.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your organisation&rsquo;s mobile device management (MDM) policies to restrict or audit Gemini&rsquo;s access to third-party app notifications, particularly on corporate Android devices. Until Google confirms a fully patched release, consider disabling Gemini&rsquo;s notification-reading capabilities via app permissions and assess whether AI assistant integrations meet your acceptable risk threshold for enterprise use.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/whatsapp-slack-notifications-could.html">WhatsApp, Slack Notifications Could Hijack Google Gemini on Android</a></p>
]]></content:encoded></item><item><title>Redis RCE Flaw CVE-2026-23479: 2-Year Bug Patched</title><link>https://zxcloudsecurity.co.uk/posts/redis-rce-vulnerability-cve-2026-23479-use-after-free-patched/</link><pubDate>Wed, 03 Jun 2026 16:40:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/redis-rce-vulnerability-cve-2026-23479-use-after-free-patched/</guid><description>Redis patches CVE-2026-23479, a use-after-free RCE flaw active since v7.2.0. Authenticated attackers could execute OS commands on the host. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html">The Hacker News</a></p>
<hr>
<p>A critical remote code execution vulnerability (CVE-2026-23479) in Redis, introduced in version 7.2.0 over two years ago, has been patched following discovery by an autonomous AI-powered bug-hunting tool. The flaw is a use-after-free bug in Redis&rsquo;s blocking-client handling code, allowing any authenticated user to execute arbitrary operating system commands on the host server. This is significant because Redis is widely deployed across cloud environments as a caching and data store layer, meaning exposure could lead to full host compromise.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Prioritise patching all Redis instances to the May 5 fixed release immediately, paying particular attention to managed Redis services (AWS ElastiCache, Azure Cache for Redis, GCP Memorystore) and self-hosted deployments — check with your vendors for patch availability. In the interim, enforce network segmentation and strict authentication controls to limit which services and users can reach Redis endpoints, reducing the authenticated-user attack surface.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/autonomous-ai-tool-finds-2-year-old-rce.html">Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)</a></p>
]]></content:encoded></item><item><title>Google DoubleClick Abused to Deliver DesckVB RAT</title><link>https://zxcloudsecurity.co.uk/posts/google-doubleclick-abused-malspam-deskvb-rat-delivery/</link><pubDate>Wed, 03 Jun 2026 16:29:16 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/google-doubleclick-abused-malspam-deskvb-rat-delivery/</guid><description>A new malspam campaign exploits Google&amp;#39;s trusted DoubleClick domain to bypass security tools and deliver the DesckVB remote access trojan to victims.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html">The Hacker News</a></p>
<hr>
<p>Attackers are exploiting Google&rsquo;s DoubleClick ad-serving domain as a redirect hop in malicious email campaigns, using its trusted reputation to bypass security filters before delivering the DesckVB remote access trojan. Because many email and web security tools whitelist or deprioritise scrutiny of well-known Google-owned domains, the technique significantly increases the likelihood of successful delivery. Once installed, a RAT gives attackers persistent remote control over the victim&rsquo;s machine.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your email and web proxy security policies to ensure that redirects through trusted domains — including Google-owned properties like DoubleClick — are still subject to full URL chain inspection and sandbox detonation. Consider enforcing policies that follow and evaluate the final destination URL rather than trusting the initial domain at face value.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html">Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT</a></p>
]]></content:encoded></item><item><title>Google DoubleClick Abused to Deliver DesckVB RAT</title><link>https://zxcloudsecurity.co.uk/posts/google-doubleclick-abused-malspam-d%D0%B5%D1%81kvb-rat-delivery/</link><pubDate>Wed, 03 Jun 2026 16:29:16 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/google-doubleclick-abused-malspam-d%D0%B5%D1%81kvb-rat-delivery/</guid><description>Attackers are exploiting Google&amp;#39;s trusted DoubleClick domain to bypass email security filters and deliver the DesckVB remote access trojan via malspam.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html">The Hacker News</a></p>
<hr>
<p>Attackers are exploiting Google&rsquo;s DoubleClick ad-serving domain as a redirect layer in malicious spam emails, using its trusted reputation to bypass security filtering tools before routing victims to attacker-controlled infrastructure that delivers the DesckVB remote access trojan. Because DoubleClick is a widely trusted Google domain, many email and web security products will not flag the initial link as suspicious. This technique is a growing trend of abusing legitimate cloud services to obscure the early stages of an attack chain.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your email and web proxy security controls to ensure they inspect the full redirect chain rather than trusting links solely based on the root domain — allowlisting DoubleClick or similar Google domains without inspecting downstream redirects creates a blind spot. Consider enforcing URL rewriting and sandboxed link-following in your email security gateway, and ensure endpoint detection controls are tuned to flag RAT behaviour post-delivery.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html">Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT</a></p>
]]></content:encoded></item></channel></rss>