A vulnerability has been discovered in Google's Gemini AI assistant for Android devices. This flaw allows unauthorized individuals to send messages from a user's locked phone. The issue potentially exposes users to misuse of their communication channels.

A newly identified vulnerability in Google's Gemini AI assistant allows unauthorized individuals with physical access to a locked Android 16 smartphone to send messages via SMS and WhatsApp without needing to enter the device's security PIN. Google has confirmed awareness of the issue and stated that a fix is scheduled for release this week.
The exploit specifically affects Android 16 devices where Gemini access from the lock screen is enabled. Reports of this bypass method have been circulating since May 2026. A security researcher detailed in May 2026 how they successfully reproduced the problem on a fully patched Pixel 6a, utilizing Gemini's "Deep Research" feature as an initial entry point.
This latest vulnerability differs from previous Gemini-based Android lock screen bypass bugs that have been reported since September 2025. The current method requires a specific multi-touch gesture to circumvent authentication.
Normally, if Gemini's access to messaging applications like SMS is revoked, attempting to send a message via Gemini from the lock screen prompts the user to enter a PIN. However, the vulnerability allows an attacker to bypass this authentication. By simultaneously pressing the "Continue" button and Gemini's "Add attachment" button, the device permits the SMS to be sent without requiring the PIN.
Furthermore, once this initial bypass is achieved, an attacker can then enable Gemini's access to other previously disconnected applications, such as WhatsApp. This is done by invoking the relevant prompt, for instance, by typing "@WhatsApp" in Gemini's text input window. Crucially, no PIN is requested or required for this subsequent action.
The changes made through this exploit are not temporary. If the legitimate owner later unlocks their phone and reviews their Gemini settings, they will find that applications like WhatsApp have been connected to Gemini, despite no PIN ever being entered to authorize these connections.
While this vulnerability necessitates physical access to the device, it poses a risk in scenarios where a phone is lost, stolen, or temporarily left unattended.
Users concerned about this vulnerability can mitigate the risk by adjusting their Gemini settings. This involves opening the Gemini app, tapping the profile picture, navigating to Settings, and selecting "Gemini on lock screen." From there, users can either completely disable "Use Gemini without unlocking" or, as a more granular option, disable "Make calls and send messages without unlocking."
Security experts note that while Google will likely patch this specific bug, the underlying challenge remains. Each new capability granted to Gemini at the lock screen inherently expands the potential attack surface, making it more difficult to ensure that only the device owner can utilize the AI assistant's features without unlocking the phone.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed