DEF CON 33 - Invoking Gemini Agents with a Google Calendar Invite - Ben Nassi, Or Yair, Stav Cohen

DEF CON 33 - Invoking Gemini Agents with a Google Calendar Invite - Ben Nassi, Or Yair, Stav Cohen

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 45:38

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Promptware represents a critical security vulnerability in LLM-powered applications like Google's Gemini, where malicious prompts in seemingly benign content (like calendar invites) can hijack the system to perform harmful actions 3:04.

Key Takeaways:
• Promptware is malicious input (text, images, or audio) that tricks LLMs into executing harmful actions, attacking the most vulnerable component in modern applications 3:04
• Researchers demonstrated how calendar invitations with injected prompts could poison Gemini's context space, leading to spam, toxic content generation, and event deletion 13:48
• Through "delayed tool invocation," attacks triggered when users say "thank you" can open windows, activate boilers, or even force users into Zoom calls 25:55
• Attackers can exfiltrate sensitive data like emails by tricking Gemini into opening URLs with embedded victim information 34:25
• Risk assessment shows 73% of these threats are high to critical, necessitating immediate mitigations 37:03

The future will likely see pure zero-click variants and more advanced promptware attacks that target automatic LLM inferences 41:53.

Sources:

  • 0:32 Introduction to promptware research
  • 3:04 Definition of promptware
  • 13:48 Short-term context poisoning
  • 25:55 IoT device control demonstration
  • 34:25 Email exfiltration attack
  • 37:03

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

So uh welcome to invitation is all you need. I will start by introducing oursel. My name is Ben. I'm a blackhead board member. I also work as freelancer consultant and I'm a faculty member at the EC department at Tel University. Together with me are uh Ora a security research team leader at uh safe bridge with seven years of experience in um security research and also staff cohen a PhD student from the technon who investigates LLM security. Now this talk is based on um a paper that can be downloaded from the website which is encoded to the QR code that you can see on the left side. And this is the agenda for today. We will start with a short trailer of this talk followed by discussing promptware. Later we'll discuss about Germany for workspace ecosystem. At the core of the talk, you will s…