Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom
## Cybersecurity Update: Exploitation of AI Assistants via Google Calendar
Cybersecurity Update: Exploitation of AI Assistants via Google Calendar
Recent research has identified a new cybersecurity threat known as "Promptware," which has the capability to exploit AI assistants by converting them into tools for unauthorized surveillance.
Researchers from Ben-Gurion University, Tel Aviv University, and Harvard have uncovered a method where a Google Calendar invite can manipulate Google's Gemini assistant to stream a victim's camera feed via Zoom.
The research paper, titled "Invitation Is All You Need," details how this attack can occur without the need for traditional malware. Instead, hackers can initiate control through a calendar invitation.
The attack utilizes a method known as Indirect Prompt Injection , where malicious instructions are embedded within text that the AI reads.
The research paper, titled "Invitation Is All You Need," details how this attack can occur without the need for traditional malware.
The Trap: A hacker sends a Google Calendar invite containing hidden malicious commands. The Infection: The AI assistant, upon reading the invite, executes the command, altering its internal processes. The Trigger: The assistant waits for a common phrase from the user to activate the command. The Spy: The assistant then executes the intended action, such as initiating a Zoom call without the user's consent.
This type of attack allows the AI to perform tasks such as unauthorized surveillance and control of smart devices. The researchers demonstrated that this method could also be used to unlock smart doors or access emails.
Google has implemented security measures to mitigate these vulnerabilities. Users are advised to be cautious of calendar invites from unknown sources, as they may contain hidden threats.
For more information, users can refer to detailed analyses of this exploit .
Based on reporting by Cyber Security News.
