Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 341, Issue 4IT NewsDevOps.com

Cybersecurity Researchers Uncover Flaw in Google AI Coding Tool

DevOps.com, Friday, August 28th, 2026

Pillar Security exploited a prompt injection in Google's Gemini CLI to gain unauthorized cloud access.

Researchers at Pillar Security found a vulnerability in Google's Gemini CLI in which hidden instructions embedded in a GitHub issue caused an AI agent to issue Workload Identity Federation credentials.

That let a researcher impersonate a privileged account and obtain Editor-level access to an internal Google Cloud project running in a sandbox.

Researcher Dan Lisichkin notes how relatively trivial it is becoming to compromise a software supply chain in the AI coding era, since malicious prompts can be planted in web pages or emails that coding agents read. Google has since remediated the flaw.

more →  ·  More from DevOps.com →