The GOP bill is called the "Make Entertainment Great Again Act," but it focuses on one particular venue: the John F. Kennedy Center for the Performing Arts. Significant obstacles stand in the way.
(Image credit: Chip Somodevilla)
The United Kingdom plans to recognize a Palestinian state in September unless Israel commits to peace in the Gaza Strip and stopping the annexation of the West Bank.
(Image credit: Toby Melville)
The wait is over, Avatar fans, as we've got a first trailer for Avatar: Fire and Ash, which is the third movie in James Cameron's sci-fi franchise and is set to be one of this year's biggest new movies.
The previous two entries in the series – 2009’s Avatar and 2022’s Avatar: The Way of Water – were both box-office smashes. Hopefully, the third installment will see similar success when it's released on December 19.
Expectations among fans of the series are certainly high, with the trailer having already amassed nine million views at the time of writing. Take a look and see it for yourself below.
What we know so far about Avatar: Fire and AshSpoilers follow for Avatar: The Way of Water. Turn back now if you haven't seen it.
The first Avatar movie has an 81% Rotten Tomatoes score from the critics. (Image credit: 20th Century Studios)The new Avatar movie certainly looks intriguing, especially as it introduces Pandora’s newest adversary.
The movie will follow on from a heartbreaking moment in Avatar: The Way of Water, which means Avatar: Fire and Ash is set to open with Jake and Neytiri’s family as they grapple with grief following the loss of Neteyam, the couple's eldest child.
The family later encounters a new, aggressive Na'vi tribe called the Ash People, who are led by the fiery tribe leader, Varang. This same tribe has allied with Jake's enemy Miles Quaritch, causing conflict on Pandora to escalate.
Fire and Ash will have a runtime of three hours and 12 minutes, making it the longest installment in the franchise so far. This is exciting news for fans wanting to dive deeper into Cameron's beautifully shot universe.
There's great news on the casting front too as Sam Worthington, Zoe Saldaña and Sigourney Weaver are all reprising their roles in this movie.
We have a while to wait until Fire and Ash is released, but it'll be one to entertain us over the holiday season. I'm really hoping for good things.
You might also likeAs he winds down his podcast after 16 years, Maron reflects on what he'll miss: "These conversations are very real conversations for me ... and that is kind of nourishing for the spirit and the soul."
Gaming kit maker Endgame Gear has confirmed it was the victim of a supply chain attack which saw unidentified threat actors break into its website and replace a legitimate configuration tool with a trojanized version containing malware.
In an announcement posted on the company’s website, it said on June 26 2025, someone managed to replace a version of the Configuration Tool for the Endgame Gear OP1w 4k v2 wireless mouse, found on its product page, with a malicious fraud.
The tainted version remained on the site until July 9, when it was removed.
Hiding the attack in plain sightthe malware acts as an infostealer, so users should change their passwords, too, especially for important accounts such as banking, work, social media, email, and similar.
The company did not discuss how the threat actors broke in, or who they were, but stressed the trojanized version was found only on the product page for that specific peripheral, while the versions found on the downloads site, GitHub, or Discord, remained clean.
Software for other peripherals was not targeted, as well.
Endgame said it only spotted the intrusion after seeing “online discussions”, meaning it was the community that flagged the attack.
A more thorough analysis has shown that access to file servers was not compromised, and customer data was not accessed.
To prevent similar incidents from happening in the future, Endgame is killing product page-specific downloads, and is centralizing all downloads on its main download page.
Furthermore, it is implementing additional malware scans and reinforcing anti-malware protections on its hosting servers.
Users who downloaded the malware are advised to remove it, and to check for the presence of the folder "C:\ProgramData\Synaptics" (it could be hidden).
They should also run a full system scan, and download a clean version.
Via BleepingComputer
You might also likeMillions of people in the world today face starvation in Gaza and in other parts of the world, from Sudan to Yemen. What happens to the body when food is lacking?
(Image credit: Hassan Jedi/Anadolu)
Capcom has announced new changes to Monster Hunter Wilds' roadmap, which includes bringing endgame content closer to release.
In a new social media post shared today, Capcom confirmed that "the expansion of endgame content" originally planned as part of Title Update 3, and set to release in late September, will now arrive as part of Ver.1.021 next month.
The content included in Title Update 3 that will now be part of Ver.1.021 includes a new level of quest difficulty, a new rewards system for the new quests featuring Talismans with random skill combinations, weapon balance adjustments, and other improvements and adjustments.
To accommodate this change, Capcom also confirmed that the release date of the upcoming update will be moved slightly out of its original release window to August 13, 2025.
(Image credit: Capcom)The "additional monster" that was revealed for Title Update 3 won't be moved forward, so fans will have to wait a little longer for that to arrive, and the contents of Title Update 4, which includes an "additional monster" and "more Challenging Hunts," are still set to arrive later in the year.
These latest roadmap changes follow the release of Title Update 2 earlier this month, which finally addressed the shader compilation issue that had been causing awful performance on PC since the game's launch.
Despite fixing the issue, the game still has an "Overwhelmingly Negative" score on Steam from 16,660 user reviews, but an overall "Mixed" score from 162,985 users.
You might also like...Google has enhanced its AI Mode in Search with a host of new features clearly aimed at encouraging people tempted by AI tools elsewhere to stick around.
AI Mode is already different from traditional search in that it sets up a more comprehensive response to your query by sending out multiple related questions based on your initial prompt. You can then ask follow-ups and adjust the thrust of your search.
With the new updates, AI mode is more of a multifaceted tool for learning and organizing information. The most immediately noticeable upgrade is that you can now upload PDFs and images to AI Mode on your desktop and ask nuanced questions about them.
On mobile, Google already lets you use AI Mode to ask questions about photos or screenshots. But making it available to desktop users means you can upload entire slide decks from a class or drag over a PDF of a book and grill the AI about the content like it’s an unpaid tutor. And the model doesn’t just respond based on your file; it will cross-reference the web to give answers that fit the context of your upload and are backed by sources and links.
Canvas planningIn case you can't get all your deep dives done in one search, the new Canvas feature offers AI Mode users a more long-term option for organizing information. Canvas appears as a side panel in AI Mode that lets you create and edit projects across multiple sessions. It's not dissimilar to the Canvas feature for ChatGPT, or indeed the Gemini Canvas tool it's clearly based on. Think of it like a cross between a collaborative document and a study planner.
You can start with a prompt about a long-term project for learning something, then hit the Create Canvas button and see the AI piece together a draft, organize resources, and respond to follow-up questions as you tweak or elaborate on your goals. Plus, you can keep returning to it even if you close the tab. Continuity is crucial if you want to do more than just a traditional Google search that ends when you close the window.
Google has plans for Canvas to support its own file uploads, too, so it will absorb some of the abilities of AI Mode's general toolkit. In fact, it seems like AI Mode will eventually look a lot like NotebookLM, though, for now, not with any AI-built podcasts.
Search LiveThe third and possibly most futuristic upgrade to AI Mode is Search Live. If Canvas is about long-term thinking, Search Live is for real-time responses.
Search Live embeds Google Lens with Google's Project Astra AI to provide answers based on the video you show it. Using Search Live, you could point your phone’s camera at any problem from a math equation on a page to a misbehaving appliance and start asking the AI questions while you're filming. The camera feed becomes the context for the AI's answers as it uses what you're seeing and saying to respond with solutions, and links as though you're FaceTiming a friend with all the answers.
This kind of live help could make people rethink what they expect from AI tools in terms of both accuracy and immediacy. Instead of a blank search box, it's looking at something, conversing about it, and delivering useful answers immediately.
That trend continues with the Google Lens upgrades coming to Chrome. Google is changing the address bar so that when you click on it, you'll be offered the option to “Ask Google about this page” and get answers about whatever website, PDF, slide, or other content is open in Chrome. You'll even be able to get AI Overviews of any section you highlight. You can then tap into AI Mode to go deeper, essentially using the web page as a starting point for a more in-depth project.
All of these changes may not feel like overnight revolutions, but they could be the basis for a new way of thinking about search. And as AI chatbots encroach on what was once Google's undisputed leadership in looking for things online, the company is no doubt hunting for competitive answers and, in the process, delivering AI search upgrades like these upgrades to us.
You might also likeNordVPN has announced the launch of Spam Call Protection. Now available to Android users in the US, the new feature alerts users to potential spam calls before they even pick up the phone. This comes as statistics signal a 33% rise in losses from scam calls in 2024.
This latest addition to NordVPN’s lineup falls under Threat Protection Pro, its suite of features that boost online security by blocking malware, phishing sites, ads, and trackers. It's a move that sees NordVPN, the best VPN according to TechRadar reviewers, extend its protection beyond the internet.
NordVPN subscribers on iPhone or located outside the US don’t need to feel left out, though. Not only are further features already in the works, but the cybersecurity company also has plans to bring Spam Call Protection to iOS and more countries.
Scam call protection with users' privacy in mind(Image credit: Nord Security)According to statistics from the FBI’s Internet Crime Complaint Center (IC3), over $50 billion has been lost to scam calls in the last five years. Losses in 2024 totaled $16.6 billion, an increase of 33% on the previous year.
What’s clear is that with rising losses from scam calls, this threat isn’t going anywhere anytime soon, which is where tools like NordVPN’s Scam Call Protection can help.
Scam Call Protection analyzes call patterns and metadata to spot spam calls. A clear warning alerts you to potential scam calls, allowing you to stay one step ahead of cybercriminals. This helps reduce the risk of successful social engineering attacks or phishing attempts, which could lead to financial loss or identity theft.
"We’ve always been about protecting people’s digital lives, and phone scams are a huge part of that threat landscape now," said Mykolas Dumcius, Chief Product Officer at NordVPN.
"The Scam Call Protection feature is our way of extending that protection beyond just internet browsing because your phone shouldn’t be a gateway for scammers either."
Crucially, NordVPN’s Scam Call Protection provides this safeguarding without accessing or storing call content, protecting user privacy in the process – that’s not guaranteed with all spam call blocking apps, as we’ve seen with the past allegations of Truecaller’s data collection.
Looking ahead: updates coming to Spam Call ProtectionNordVPN: Today's best VPN
Our reviewers rank NordVPN as the best VPN service on the market right now for privacy, security, unblocking, and speed. Sign up to NordVPN today to claim TechRadar's exclusive deal and get up to 76% discount, up to $50 of Amazon Gift cards, and 4 months free protection – or you can still use its 30-day money-back guarantee if you're unhappy.View Deal
“NordVPN is already working on several enhancements to make the feature even more effective,” said Dumcius.
NordVPN subscribers can expect to see the addition of caller ID to help users separate legitimate numbers from scam ones. Specific call categories will provide users with a better idea of who’s calling, whether that’s a banking institution, healthcare provider, or otherwise.
Users will also have the chance to contribute to and improve Spam Call Protection’s call ID database themselves by flagging suspicious numbers as part of a user reporting system.
If you’re a NordVPN Plus, Complete, or Prime user in the US, you’ll already have access to this new feature. To take advantage, you need only open NordVPN’s Android app, navigate to Threat Protection, and toggle the Spam Call Protection feature – an active VPN connection isn’t required either.
You might also likeFive EU countries are set to test an age verification app to protect children online.
Denmark, Greece, Spain, France, and Italy are the first to test the technical solution unveiled by the European Commission on July 14, 2025.
The announcement came less than two weeks before the UK enforced mandatory age verification checks on July 25. These have so far sparked concerns about the privacy and security of British users, fueling a spike in usage amongst the best VPN apps.
The EU's age verification blueprint(Image credit: Photo by Leon Neal/Getty Images)As the European Commission explains on its website, the age verification blueprint enables users to prove they are over 18 "without revealing any other personal information."
"It is based on open-source technology and designed to be robust, user-friendly, privacy-preserving, and fully interoperable with future European Digital Identity Wallets," the Commission explains.
The introduction of this technical solution is a key step in implementing children's online safety rules under the Digital Services Act (DSA).
Lawmakers ensure that this solution seeks to set "a new benchmark for privacy protection" in age verification.
That's because online services will only receive proof that the user is 18+, without any personal details attached.
Further work on the integration of zero-knowledge proofs is also ongoing, with the full implementation of mandatory checks in the EU expected to be enforced in 2026.
What's happening in the UK?Starting from Friday, July 25, millions of Britons will need to be ready to prove their age before accessing certain websites or content.
Under the Online Safety Act, sites displaying adult-only content must prevent minors from accessing their services via robust age checks.
Social media, dating apps, and gaming platforms are also expected to verify their users' age before showing them so-called harmful content.
As the UK's regulator body, Ofcom explains on its website, service providers can use several methods to confirm users' age. These span from face scans to estimate people's age to bank or credit card age checks, ID wallets, mobile network operator age checks, photo-ID matching, and even email-based age estimation.
The vagueness of what constitutes harmful content, as well as the privacy and security risks linked with some of these age verification methods, have attracted criticism among experts, politicians, and privacy-conscious citizens who fear a negative impact on people's digital rights.
While the EU approach seems better on paper, it remains to be seen how the age verification scheme will ultimately be enforced.
Commenting on this point, the CEO of Swedish VPN provider, Mullvad, told TechRadar: "The EU [approach] is more planned, it took the EU 12 years. In the UK looks like [there is] no plan at all."
You might also likeMicrosoft and Asus' ROG Xbox Ally X and ROG Xbox Ally handhelds were announced earlier in June, with an anticipated late 2025 launch date. However, that may not be as accurate as initially expected.
According to reliable leaker Billbil-kun via Dealabs, both ROG Xbox Ally models will launch on August 20, with pre-orders going live during Gamescom 2025. The new leak also corroborates the previous price rumors; the ROG Xbox Ally X will reportedly be priced at $899, and the ROG Xbox Ally at $599. Pricing in other regions could vary due to factors such as inflation and tariffs.
It's worth noting that Microsoft will be present at Gamescom in August, with hands-on opportunities for fans at the Xbox booth, so it lines up well with the leak suggesting an August 20 launch date. The long-anticipated Hollow Knight: Silksong will also be available to test at the popular large-scale game expo.
If this leak is legitimate, it could mean that Silksong will also launch on August 20, as Xbox President Sarah Bond previously confirmed that the title will be available on Game Pass at launch of the new handhelds. Essentially, it may act as a shadow drop, which Microsoft has done before with The Elder Scrolls 4: Oblivion Remastered, and August may be the month to look forward to for Xbox and PC fans.
While we still need to await Microsoft's full confirmation, it appears as though the ROG Xbox Ally handhelds will rival the MSI Claw A8, which has also been rumored to launch in August – and Microsoft and Asus may have the edge in that battle with a less expensive option.
(Image credit: Team Cherry)Analysis: The ROG Xbox Ally X's price is a huge dealbreaker, but at least there's a cheaper alternativeI've been highly critical of handheld gaming PC manufacturers lately due to the huge leap in pricing for new devices, and we can see the same thing happening here with the ROG Xbox Ally X. However, I'm pleased to at least see that there is an inexpensive alternative – which is one aspect some mainstream handheld makers like MSI consider with new releases.
Having seen the underwhelming performance leap from AMD's Ryzen Z1 Extreme to the Ryzen Z2 Extreme, I don't think I could recommend the ROG Xbox Ally X at $899. While it's using a slightly different Ryzen AI Z2 Extreme processor, I don't expect that to be too different from its standard version, at least when it comes to game performance.
As I stated in my previous piece, I'm not pleased to see prices nearly reach $1,000 for handheld gaming PCs, but gamers aren't necessarily being completely priced out here, with the Ryzen Z2 A ROG Xbox Ally model at $599. Of course, we still need official confirmation on pricing, but if the latter model's price is this low, I'll have to give credit where credit is due.
Let's just hope there's enough availability, and prices don't suddenly spiral out of control.
You might also like...VPN demand in the UK has soared overnight since new age verification checks were enforced, as Brits look for ways to bypass new requirements. This has sparked concerns that authorities could end up banning their use.
The UK's science secretary, Peter Kyle, asserts there are no plans to ban VPNs. Kyle confirmed, however, that the government would be looking "very closely" at how the best VPN apps are being used.
"Some people are finding their way round [the legislation]. Very few children will be going actively out there searching for harmful content," said Kyle during an interview with Sky News today, July 29, 2025 – The Guardian reported.
A virtual private network (VPN) encrypts your internet connections, while spoofing you real IP address location. (Image credit: Getty Images)Starting from Friday, July 25, 2025, all platforms displaying adult-only or harmful content must enforce robust age verification checks under the Online Safety Act.
As Ofcom explains on its website, "Just ticking a box to say you're over 18 will no longer be enough."
This means that all websites reserved for users over 18 must ensure minors never access their services via ID checks. Crucially, social media, dating apps, and gaming platforms are also expected to verify their users' age before displaying them potentially dangerous materials.
These new requirements have thus far sparked concerns regarding data privacy, security, free speech, and access to information.
A petition to repeal the UK Online Safety Act has already reached over 340,000 at the time of writing.
Reform UK's leader, Nigel Farage, is also strongly pushing to scrap what he described as a "borderline dystopian" legislation – The Guardian reported.
VPNs and age checks – what to knowNordVPN: Today's best VPN
Our reviewers rank NordVPN as the best VPN service on the market right now for security and performance. A great track record in unblocking geo-restrictions and streaming platforms, coupled with a huge server network across the world, will enable you to set your IP address for any country of your choosing.
Sign up to NordVPN today to claim TechRadar's exclusive deal and get up to 76% discount, up to $50 Amazon Gift card, and 4 months free protection – you can still use its 30-day money-back guarantee.View Deal
VPN services are a popular way to bypass geo-restrictions, like those imposed by streaming platforms. That's because a VPN spoofs your real IP address and assigns you a new, temporary one based in the same place as the VPN server you join. This makes it possible to trick the sites you visit into thinking you're in a different country.
Considering the sudden spike in VPN usage across the country, people in the UK are likely familiar with this.
A popular provider, Proton VPN, recorded an hourly increase of over 1,400% starting from Friday at midnight. AdGuard VPN also confirmed to TechRadar that sign-ups grew by 2.5 times in just a few days. Data from Top10VPN shows an ongoing surge in VPN demand of over 500% since Friday.
At the time of writing, using a VPN in the UK is completely legal, and using one to bypass the new age checks should not be considered a crime.
The UK's regulator body for online safety, Ofcom, however, is strongly suggesting against their use. Clearly, without much success so far.
Will the government find a way to prevent people from bypassing the new Online Safety Act's measures via VPNs?
It's too early to know for certain, but a ban seems to be off the cards – for now, at least.
You might also likeWhile it has no release date, Netflix’s upcoming Pride and Prejudice adaptation now has a fully confirmed cast. Olivia Colman and Rufus Sewell will lead the Bennet family, with Emma Corrin, Freya Mavor, Hopey Parish, Holley Avery and Rhea Norwood as the infamous Bennet women. Jack Lowden will be our Mr. Darcey, with Daryl McCormack as Mr. Bingley. The names don’t stop there, though, with Fiona Shaw playing Lady Catherine de Bourgh and Jamie Demetriou joining as Mr. Collins.
However, none of these characters are who I actually have an issue with. You might have noticed that there are a lot of Jane Austen adaptations that have graced our screens over the years. From the infamous Pride and Prejudice movies that helped give the tale the cultural capital it has today, to Netflix’s previous take on Austen’s Persuasion that got absolutely battered online, there’s been more than anyone could count. So, surely if you’re going to add yet another title to the pile, it has to be pitch perfect.
While the Bennet women totally hit the mark, it’s the casting of Mr. Wickham that has got my back up. Take one brick out of the pile and it all falls down, and much like a lost game of Jenga, Louis Partridge’s casting announcement is the one that spoils it all for Netflix.
Louis Partridge isn’t the right age fit for Mr. Wickham in Netflix’s Pride and Prejudice remakeLouis Partridge in The Lost Girls. (Image credit: Amazon Prime Video)If you’ve read the original book – and just about every bookish girl in their 20s and 30s will be watching Dolly Alderton’s take with a scathing eye – you’ll know Mr. Wickham is an abhorrent man. A manipulative militia officer who (in 2025 terms) is a total wasteman, Wickham is best known for predatory behaviour, lying and gambling. In short, this means he needs to be a little older and more strung-out than the rest of his cast.
Enter 22-year-old Patridge, who is at least seven years younger than the majority of his immediate co-stars. While his long locks and chiseled jaw are objectively ideal for a period drama, his baby face and sweet eyes don’t match the abusive personality he’s been assigned. Even though he’s an incredibly promising actor, I’m not entirely convinced he’ll be able to pull this one off.
Of course, none of this is Partridge’s fault. It’s more of a testament to just how lazy the supposed best streaming service in the world is being when it comes to their adaptations. Considering how Persuasion went down the last time Netflix attempted Austen, it can’t even guarantee a healthy amount of viewers to make production worthwhile. So, what does the streamer think it can add to the value of one of the most famous fictional IPs? My guess is it doesn’t think it needs to, it’s merely riding on the coattails of a well-known story very few people dislike.
Netflix and Partridge, prove me wrong. If we really do stand to benefit from another Pride and Prejudice adaptation, I’m prepared to eat my bonnet. But If I’m right, and I suspect I am, no casting announcement in the world could save me from riding off on my high horse.
You might also likeWarner Bros. Discovery (WBD) will soon be Warner Bros. once more. Following the announcement in early June that the media company would separate into two, WBD has revealed the new corporate names of its new businesses.
Like it did with HBO Max at the start of the month, which changed back to HBO Max after a two-year stint as Max (who could forget the Spider-Men meme that HBO Max's chief marketing officer Shauna Spenley shared during the rebrand's announcement), WBD is reverting back to the name it's most commonly known as.
V2 approved by legal. pic.twitter.com/uUhH3RU4T6May 14, 2025
The change will take effect in mid-2026 and will see Warner Bros. become the home of Warner Bros. Television, Warner Bros. Motion Picture Group, DC Studios, HBO, HBO Max and Warner Bros. Gaming Studios, as well as the studio's legendary movie and TV content.
Meanwhile, the newly formed Discovery Global will include the TV networks CNN, TNT Sports in the US, Discovery, and some free-to-air channels across Europe such as Quest and Food Network as well as streaming services such as the Discovery+ and the Bleacher Report (B/R).
Effectively, the split means that Warner Bros. will house all of WBD's main streaming services and studios, while Discovery Global will become the place for premier entertainment, sports and news networks.
The decision to split Warner Bros. and Discovery Global is similar to Comcast's plan to spinoff NBCUniversal's struggling cable portfolio into a new company called Versant. Just like Warner Bros., NBCU will be the new home for its studios, the streaming service Peacock, and the networks NBC and Bravo.
What does the Warner Bros. and Discovery Global split mean for subscribers?The decline of linear TV is no secret. Since the introduction of the best streaming services, on-demand content has grown significantly in popularity, particularly for its accessibility, flexible pricing and convenience.
That's left cable networks scrambling to tempt back viewers, and as a result many media companies have launched streaming services of their own to counter the decline in profits and help balance the financial strain.
One way to help offset that debt is to restructure a business, which is exactly what WBD has done, splitting off its burdened cable networks from its most profitable assets, including its streaming service HBO Max.
However, the move also means that its other streaming platforms, Discovery+ and CNN (not the service that was shut down in 2022 but the new one launching later this year), will now be part of Discovery Global. While the platform – which is known for real-life entertainment and includes content from networks such as Magnolia Network, HGTV, Food Network, TLC, ID, Animal Planet and the Discovery Channel – will remain independent, subscribers can expect some changes to the content they see.
The biggest potential change is that HBO Max will likely no longer be the home for sports content from its TNT Sports and Bleacher Reports networks in the US. That will likely be the same for CNN content that's currently available on HBO Max, too (although WBD has said that CNN Max will remain, despite the launch of its new standalone service).
However, while that's not yet confirmed for those in the US, a WBD spokesperson has reportedly told RXTV that TNT Sports will be available on HBO Max when it eventually launches in the UK sometime in 2026.
It's not yet clear how the split will impact the content you see on HBO Max and Discovery+, but considering that both platforms have been merging some of their content together in the years since WarnerMedia merged with Discovery, there's bound to be some changes to subscribers next year as the two companies separate.
You might also likeA security flaw in Google’s new Gemini CLI tool allowed threat actors to target software developers with malware, even exfiltrating sensitive information from their devices, without them ever knowing.
The vulnerability was discovered by cybersecurity researchers from Tracebit just days after Gemini CLI was first launched on June 25, 2025.
Google released a fix with the version 0.1.14, which is now available for download.
Hiding the attack in plain sightGemini CLI is a tool that lets developers talk to Google’s AI (called Gemini) directly from the command line. It can understand code, make suggestions, and even run commands on the user’s device.
The problem stems from the fact that Gemini could automatically run certain commands that were previously placed on an allow-list. According to Tracebit, there was a way to sneak hidden, malicious instructions into files that Gemini reads, like README.md.
In one test, a seemingly harmless command was paired with a malicious one that exfiltrated sensitive information (such as system variables or credentials) to a third-party server.
Because Gemini thought it was just a trusted command, it didn’t warn the user or ask for approval. Tracebit also says the malicious command could be hidden using clever formatting, so users wouldn’t even see it happening.
"The malicious command could be anything (installing a remote shell, deleting files, etc),” the researchers explained.
The attack is not that easy to pull off, though. It requires a little setting up, including having a trusted command on the allow-list, but it could still be used to trick unsuspecting developers into running dangerous code.
Google has now patched the problem, and if you’re using Gemini CLI, make sure to update to version 0.1.14 or newer as soon as possible. Also, make sure not to run it on unknown, or untrusted code (unless you’re in a secure test environment).
Via BleepingComputer
You might also like