Unless users take action, Android will let Gemini access third-party apps

Starting today, Google is implementing a change that will enable its Gemini AI engine to interact with third-party apps, such as WhatsApp, even when users previously configured their devices to block such interactions. Users who don’t want their previous settings to be overridden may have to take action.

An email Google sent recently informing users of the change linked to a notification page that said that “human reviewers (including service providers) read, annotate, and process” the data Gemini accesses. The email provides no useful guidance for preventing the changes from taking effect. The email said users can block the apps that Gemini interacts with, but even in those cases, data is stored for 72 hours.

An email Google recently sent to Android users.

An email Google recently sent to Android users.

No, Google, it’s not good news

The email never explains how users can fully extricate Gemini from their Android devices and seems to contradict itself on how or whether this is even possible. At one point, it says the changes “will automatically start rolling out” today and will give Gemini access to apps such as WhatsApp, Messages, and Phone “whether your Gemini apps activity is on or off.” A few sentences later, the email says, “If you have already turned these features off, they will remain off.” Nowhere in the email or the support pages it links to are Android users informed how to remove Gemini integrations completely.

Compounding the confusion, one of the linked support pages requires users to open a separate support page to learn how to control their Gemini app settings. Following the directions from a computer browser, I accessed the settings of my account’s Gemini app. I was reassured to see the text indicating no activity has been stored because I have Gemini turned off. Then again, the page also said that Gemini was “not saving activity beyond 72 hours.”

https://arstechnica.com/security/2025/07/unless-users-take-action-android-will-let-gemini-access-third-party-apps/




TikTok is being flooded with racist AI videos generated by Google’s Veo 3

TikTok notes that it uses both technology and human moderators to identify rule-breaking content. However, the volume of uploads makes timely moderation difficult. While the racist videos racked up a lot of views, a TikTok spokesperson tells Ars that more than half of the accounts cited in the MediaMatters report were banned for policy violations before the report was published, and the remainder have now been removed.

As for Google, it has a comprehensive Prohibited Use Policy that bans the use of its services to promote hate speech, harassment, bullying, intimidation, and abuse. The videos uncovered by MediaMatters all seem to fall under one or more of these categories. In a perfect world, Veo 3 would refuse to create these videos, but vagueness in the prompt and the AI’s inability to understand the subtleties of racist tropes (i.e., the use of monkeys instead of humans in some videos) make it easy to skirt the rules.

TikTok, being the world’s leading social video behemoth, is a natural place for these videos to spread. It’s not exclusive to TikTok, though. X (formerly Twitter) has gained a reputation for very limited moderation, leading to an explosion of hateful AI content. This problem could also get worse very soon. Google has plans to integrate Veo 3 into YouTube Shorts, which could make it even easier for similar content to spread on YouTube.

TikTok and Google have clear prohibitions on this content, which should have prevented it from being seen millions of times on social media. Enforcement of those policies, however, is lacking. TikTok is seemingly unable to keep up with the flood of video uploads, and Google’s guardrails appear insufficient to block the creation of this content. We’ve reached out to Google to inquire about Veo 3’s safety features but have not yet heard back.

For as long as generative AI has existed, people have used it to create inflammatory and racist content. Google and others always talk about the guardrails to prevent misuse, but they can’t catch everything. The realism of Veo 3 makes it especially attractive for those who want to spread hateful stereotypes. Maybe all the guardrails in the world won’t stop that.

https://arstechnica.com/ai/2025/07/racist-ai-videos-created-with-google-veo-3-are-proliferating-on-tiktok/




Facebook inizia ad alimentare la sua AI con foto private e non pubblicate

Meta sta espandendo la sua raccolta di dati per addestrare i modelli di AI includendo potenzialmente anche immagini non pubblicate presenti nei dispositivi degli utenti di Facebook. In passato, l’azienda ha fatto affidamento su miliardi di immagini caricate pubblicamente su Facebook e Instagram.

Ora, mediante la funzione ‘cloud processing’, alcuni utenti stanno ricevendo notifiche che li invitano ad attivare un’opzione che carica regolarmente contenuti dalla propria galleria fotografica sul cloud di Meta.

Questa scelta permette alla AI di analizzare le immagini inedite per generare contenuti personalizzati come collage, ricapitolazioni, o effetti AI su misura per eventi specifici.

Tuttavia, l’attivazione di questa funzione implica anche l’accettazione dei termini di utilizzo di Meta AI, che includono l’analisi automatica di caratteristiche facciali, dati temporali e riconoscimento di oggetti o persone nei contenuti.

Nonostante Meta abbia dichiarato a The Verge di non utilizzare attualmente queste foto per addestrare i propri modelli, ha evitato di chiarire se tale scenario possa verificarsi in futuro.

Questo solleva importanti interrogativi sulla gestione della privacy e sul consenso consapevole, soprattutto alla luce del fatto che l’azienda ha già ammesso di aver utilizzato tutti i contenuti pubblicati dal 2007 in poi per istruire i propri sistemi generativi.

L’ambiguità nel definire cosa sia “pubblico” e chi sia considerato un “utente adulto” in quegli anni alimenta ulteriori dubbi e preoccupazioni su possibili abusi e carenze normative.

Per maggiori informazioni, clicca per l’articolo originale.

Le emissioni di Google aumentano del 51% a causa della domanda energetica dell’AI, ostacolando gli sforzi ecologici

Le emissioni di carbonio di Google sono aumentate del 51% rispetto al 2019, compromettendo in modo significativo il percorso dell’azienda verso la sostenibilità ambientale. Questo incremento è dovuto principalmente alla crescente richiesta di energia necessaria per l’addestramento e il funzionamento dei modelli di AI, che hanno causato un’espansione dei data center a livello globale.

Sebbene Google abbia investito in energia rinnovabile e tecnologie per la rimozione del carbonio, non è riuscita a contenere le cosiddette ‘emissioni scope 3’, che includono quelle legate alla catena di approvvigionamento e rappresentano la fetta più ampia del totale.

Secondo quanto riportato, il consumo elettrico di Google è cresciuto del 27% in un solo anno, mentre le previsioni per il 2026 indicano che i data center, alimentati in gran parte dall’AI, richiederanno una quantità di energia pari a quella consumata dal Giappone. Inoltre, si prevede che entro il 2030 rappresenteranno il 4,5% del consumo energetico globale.

La scarsità di progressi nell’adozione di tecnologie a basse emissioni di carbonio, come i reattori nucleari modulari (SMR), ostacola ulteriormente la decarbonizzazione dell’infrastruttura digitale.

Nonostante ciò, Google sostiene che l’AI potrebbe, nel lungo termine, contribuire positivamente alla riduzione delle emissioni globali, grazie ad applicazioni capaci di ottimizzare il consumo energetico e promuovere soluzioni ambientali.

L’obiettivo dichiarato è quello di ridurre 1 gigatonnellata di emissioni all’anno entro il 2030 attraverso strumenti AI. Tuttavia, le attuali proiezioni sollevano dubbi sulla sostenibilità di questo sviluppo, specialmente in assenza di incentivi regolatori e tecnologie scalabili.

Per maggiori informazioni, clicca per l’articolo originale.

Leggi le altre notizie sull’home page di Key4biz

https://www.key4biz.it/facebook-inizia-ad-alimentare-la-sua-ai-con-foto-private-e-non-pubblicate/537183/




Android phones could soon warn you of “Stingrays” snooping on your communications

Smartphones contain a treasure trove of personal data, which makes them a worthwhile target for hackers. However, law enforcement is not above snooping on cell phones, and their tactics are usually much harder to detect. Cell site simulators, often called Stingrays, can trick your phone into revealing private communications, but a change in Android 16 could allow phones to detect this spying.

Law enforcement organizations have massively expanded the use of Stingray devices because almost every person of interest today uses a cell phone at some point. These devices essentially trick phones into connecting to them like a normal cell tower, allowing the operator to track that device’s location. The fake towers can also shift a phone to less secure wireless technology to intercept calls and messages. There’s no indication this is happening on the suspect’s end, which is another reason these machines have become so popular with police.

However, while surveilling a target, Stingrays can collect data from other nearby phones. It’s not unreasonable to expect a modicum of privacy if you happen to be in the same general area, but sometimes police use Stingrays simply because they can. There’s also evidence that cell simulators have been deployed by mysterious groups outside law enforcement. In short, it’s a problem. Google has had plans to address this security issue for more than a year, but a lack of hardware support has slowed progress. Finally, in the coming months, we will see the first phones capable of detecting this malicious activity, and Android 16 is ready for it.

https://arstechnica.com/gadgets/2025/06/future-android-phones-could-warn-you-about-data-stealing-fake-cell-towers/




Prompt injection indiretta, Google migliora la sua strategia di sicurezza a più livelli per l’IA


Tra le minacce più preoccupanti per i sistemi di intelligenza artificiale c’è la prompt injection indiretta, una tecnica che, a differenza di quella diretta, nasconde istruzioni malevole in sorgenti esterne, come inviti a riunioni, email o documenti. Per proteggersi da questa modalità di prompt injection, Google sta integrando nuove misure di sicurezza a più livelli nei propri strumenti.

La strategia “stratificata” del gigante tech prevede misure di sicurezza a ogni livello del ciclo di vita del prompt per rendere più difficile il lavoro dell’attaccante, in modo che “siano costretti ad affidarsi a metodi più facili da individuare o che richiedono più risorse” afferma il team GenAI Security di Google.

Google prompt injection

La difesa di Google contro l’iniezione indiretta di comandi comincia proprio dal prompt: la compagnia sta rilasciando dei modelli di machine learning in grado di individuare prompt e istruzioni malevole in diverse forme, comprese email e file. “Quando gli utenti cercano dati su Workspace con Gemini, i classificatori di contenuti filtrano i dati pericolosi che contengono istruzioni malevole” continua il team di sicurezza della compagnia.

Il secondo livello di protezione prevede un ulteriore controllo sul prompt che obbliga l’LLM a eseguire esclusivamente l’istruzione richiesta dall’utente, ignorando qualsiasi altra istruzione che potrebbe essere presente nel contenuto da caricare. 

Il terzo livello di protezione agisce sugli URL delle immagini esterne, impedendo all’LLM di renderizzarle, e segnala qualsiasi URL sospetto senza includerlo nella risposta.

Credits: Google

Dal prossimo futuro Gemini richiederà, come ulteriore misura di protezione, un sistema di conferma utente per eseguire determinate azioni; “Per esempio, operazioni potenzialmente rischiose come cancellare un evento dal calendario scatenerebbe una richiesta di conferma per l’utente, aiutando così a prevenire l’esecuzione immediata e nascosta dell’operazione” chiarisce Google.

Infine, come ultima misura di sicurezza contro la prompt injection indiretta, Gemini notificherà all’utente l’eventuale presenza di allegati e contenuti malevoli, cancellando la risposta generata.

“La nostra strategia di sicurezza completa contro la prompt injection rafforza l’intero framework di sicurezza per Gemini“ afferma il team di Google. Oltre alle tecniche integrate nell’LLM, la compagnia ha annunciato nuovi test manuali e automatici di red teaming, l’uso di robusti standard di sicurezza come il Secure AI Framework (SAIF) e nuove partnership sia con ricercatori tramite il programma VRP (Vulnerability Reward Program) che con altre aziende tech grazie alla Coalition for Secure AI (CoSAI).

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/06/24/prompt-injection-indiretta-google-la-sua-strategia-di-sicurezza-a-piu-livelli/?utm_source=rss&utm_medium=rss&utm_campaign=prompt-injection-indiretta-google-la-sua-strategia-di-sicurezza-a-piu-livelli




Cybercriminali russi aggirano l’MFA di Gmail con una campagna di phishing sofisticata


Il team del Google Threat Intelligence ha pubblicato una nuova analisi in cui descrive una nuova campagna di phishing che consente agli attaccanti di aggirare l’MFA di Gmail grazie alle Application Specific Password (ASP).

Le ASP sono passcode di 16 cifre che consentono a un’applicazione o a un dispositivo meno sicuri di accedere a un Account Google con attiva l’autenticazione multi-fattore. Da documentazione Google sconsiglia l’utilizzo delle ASP.

MFA Gmail

La campagna del gruppo si basa sul convincere la vittima a creare e condividere uno screenshot di una ASP per permettere agli attaccanti di accedere all’account senza dover gestire l’MFA. Come riportato anche da The Citizen Lab, la prima notifica dell’attacco è arrivata da Keir Giles, un noto ricercatore inglese attivo nel controspionaggio contro la Russia.

Il 22 maggio Giles ha ricevuto un’email in cui il mittente era una certa “Claudie S. Weber” del Dipartimento di Stato statunitense. Nel messaggio Weber invitava Giles a un meeting con lei e alcuni suoi colleghi per parlare di alcuni “recenti sviluppi”, senza specificare di cosa si trattasse. Alcuni degli indirizzi email in CC terminavano con @state.gov, un trucco degli attaccanti per far apparire la comunicazione legittima.

Giles ha voluto approfondire la questione e ha risposto alla mail; tale Weber allora ha inviato un PDF con le istruzioni per registrare un account guest per conversare coi membri del Dipartimento dello Stato. Il PDF, che a una prima occhiata sembra legittimo, richiede alle vittime di navigare su un link Google per creare una ASP; in seguito, gli attaccanti chiedono all’utente di condividere con loro il codice di 16 cifre generato, apparentemente per consentirgli di accedere alla piattaforma del Dipartimento.

Il codice viene invece utilizzato dal gruppo per prendere il controllo dell’account Google della vittima, riuscendo di conseguenza ad accedere a tutte le email scambiate. Gli attaccanti hanno utilizzato per lo più proxy residenziali e server VPS per accedere agli account.

L’attacco a Gmail che supera l’MFA: la risposta di Google

Secondo il Google Threat Intelligence Group, dietro gli attacchi ci sarebbe UNC6293, un gruppo di cybercriminali che opera per conto del governo russo. Il team di sicurezza ritiene che il gruppo possa essere legato ad APT29, un’altra gang russa nota per aver distribuito la backdoor WINELOADER, anche se non ci sono indicazioni certe di una qualche relazione.

I ricercatori di The Citizen Lab sottolineano che l’attacco è altamente sofisticato e che richiede una preparazione molto attenta: il gruppo ha creato numerosi account falsi per far apparire le comunicazioni come legittime e hanno posto molta attenzione al tono dei messaggi scambiati, senza mai far nascere il senso di urgenza nella vittima.

“L’interazione si è svolta in più di 10 scambi nel corso di diverse settimane, dimostrando una notevole pazienza da parte degli attaccanti” spiegano i ricercatori.  “Gli autori dell’attacco erano anche pronti con le risposte e preparati ad adattarsi in base alle repliche di Giles. Ad esempio, dopo che Giles ha affermato che non sarebbe riuscito a partecipare al meeting nella data proposta, gli autori dell’attacco hanno scelto di non esercitare pressioni o urgenza in modo esplicito, suggerendo invece di creare la piattaforma per il futuro“.

Il gruppo è effettivamente riuscito a convincere Giles a creare e condividere l’ASP, anche su diversi account. Google ha in seguito identificato l’attacco e ha disabilitato le email degli attaccanti, oltre che gli account compromessi. In un post su X, Giles ha confermato che c’è stato un login sospetto al suo account e ha quindi avvertito i suoi contatti di trattare con la massima attenzione eventuali comunicazioni o allegati inviati da uno dei suoi indirizzi email.

Oltre a quella che ha colpito Giles, Google ha individuato anche un’altra campagna analoga del gruppo che sfruttava invece figure legate al governo ucraino.

Visto il livello di sofisticazione della campagna e le personalità centrali prese di mira dagli attaccanti, la compagnia di Mountain View consiglia agli utenti a rischio di aderire al suo Advanced Protection Program volto a tutelare gli account che hanno elevata visibilità e gestiscono informazioni sensibili. Il programma, tra le altre cose, comprende il blocco della creazione di ASP.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/06/23/cybercriminali-russi-aggirano-l-mfa-di-gmail-con-una-campagna-di-phishing-sofisticata/?utm_source=rss&utm_medium=rss&utm_campaign=cybercriminali-russi-aggirano-l-mfa-di-gmail-con-una-campagna-di-phishing-sofisticata




Google’s frighteningly good Veo 3 AI videos to be integrated with YouTube Shorts

Even in the age of TikTok, YouTube viewership continues to climb. While Google’s iconic video streaming platform has traditionally pushed creators to produce longer videos that can accommodate more ads, the site’s Shorts format is growing fast. That growth may explode in the coming months, as YouTube CEO Neal Mohan has announced that the Google Veo 3 AI video generator will be integrated with YouTube Shorts later this summer.

According to Mohan, YouTube Shorts has seen a rise in popularity even compared to YouTube as a whole. The streaming platform is now the most watched source of video in the world, but Shorts specifically have seen a massive 186 percent increase in viewership over the past year. Mohan says Shorts now average 200 billion daily views.

YouTube has already equipped creators with a few AI tools, including Dream Screen, which can produce AI video backgrounds with a text prompt. Veo 3 support will be a significant upgrade, though. At the Cannes festival, Mohan revealed that the streaming site will begin offering integration with Google’s leading video model later this summer. “I believe these tools will open new creative lanes for everyone to explore,” said Mohan.

YouTube Shorts recommendations.

YouTube heavily promotes Shorts on the homepage.

Credit: Google

YouTube heavily promotes Shorts on the homepage. Credit: Google

This move will require a few tweaks to Veo 3 outputs, but it seems like a perfect match. As the name implies, YouTube Shorts is intended for short video content. The format initially launched with a 30-second ceiling, but that has since been increased to 60 seconds. Because of the astronomical cost of generative AI, each generated Veo clip is quite short, a mere eight seconds in the current version of the tool. Slap a few of those together, and you’ve got a YouTube Short.

https://arstechnica.com/gadgets/2025/06/googles-veo-3-ai-videos-will-come-to-youtube-shorts-this-summer/




Google’s Gemini AI family updated with stable 2.5 Pro, super-efficient 2.5 Flash-Lite

Google has announced a big expansion of its Gemini AI model family today. After months of tweaking and tuning, the high-power Gemini 2.5 Pro is leaving preview and is ready for developers to build on. Meanwhile, Google is offering a peek at its upcoming high-efficiency model, known as Gemini 2.5 Pro Flash-Lite. Try as it might, Google can’t get away from confusing model names.

Google’s AI aspirations have been looking up in 2025 with the debut of Gemini 2.5. These models showed a marked improvement over past versions, making Google more competitive with OpenAI and its popular GPT models. However, we’ve been inundated with previews and test builds as Google works toward general availability, which means a model is stable enough for long-term development work.

The 2.5 Flash model left preview at I/O, but Gemini 2.5 Pro lagged behind. Today, Flash is hitting general availability with the 04-17 build. Gemini 2.5 Pro is leaving preview and also reaching general availability, and as predicted, the recently revamped 06-05 build is the winner. This version aimed to address some issues that popped up in the Google I/O build of 2.5 Pro, and it appears to have worked.

Gemini final models

Google now has a Gemini model for every task.

Credit: Google

Google now has a Gemini model for every task. Credit: Google

All Gemini 2.5 models include adjustable thinking budgets, making them appealing to developers who want more control over costs. For the most price-sensitive devs, Google is also introducing Gemini 2.5 Flash-Lite, which was previously experimental. This model is now in preview, offering a way to run high-volume AI workloads without incurring significant costs. Compared to 2.5 Flash, it’s one-third of the cost for text, image, and video inputs and less than one-sixth of the cost for output tokens. It’s unlikely this variant of Gemini will come to the app for regular users, because it’s less capable than 2.5 Flash and only makes sense when you’re paying by the token.

https://arstechnica.com/ai/2025/06/googles-gemini-ai-family-updated-with-stable-2-5-pro-super-efficient-2-5-flash-lite/




OpenAI weighs “nuclear option” of antitrust complaint against Microsoft

OpenAI executives have discussed filing an antitrust complaint with US regulators against Microsoft, the company’s largest investor, The Wall Street Journal reported Monday, marking a dramatic escalation in tensions between the two long-term AI partners. OpenAI, which develops ChatGPT, has reportedly considered seeking a federal regulatory review of the terms of its contract with Microsoft for potential antitrust law violations, according to people familiar with the matter.

The potential antitrust complaint would likely argue that Microsoft is using its dominant position in cloud services and contractual leverage to suppress competition, according to insiders who described it as a “nuclear option,” the WSJ reports.

The move could unravel one of the most important business partnerships in the AI industry—a relationship that started with a $1 billion investment by Microsoft in 2019 and has grown to include billions more in funding, along with Microsoft’s exclusive rights to host OpenAI models on its Azure cloud platform.

The friction centers on OpenAI’s efforts to transition from its current nonprofit structure into a public benefit corporation, a conversion that needs Microsoft’s approval to complete. The two companies have not been able to agree on details after months of negotiations, sources told Reuters. OpenAI’s existing for-profit arm would become a Delaware-based public benefit corporation under the proposed restructuring.

The companies are discussing revising the terms of Microsoft’s investment, including the future equity stake it will hold in OpenAI. According to The Information, OpenAI wants Microsoft to hold a 33 percent stake in a restructured unit in exchange for foregoing rights to future profits. The AI company also wants to modify existing clauses that give Microsoft exclusive rights to host OpenAI models in its cloud.

https://arstechnica.com/ai/2025/06/openai-weighs-nuclear-option-of-antitrust-complaint-against-microsoft/




Another one for the graveyard: Google to kill Instant Apps in December

But that was then, and this is now. Today, an increasing number of mobile apps are functionally identical to the mobile websites they are intended to replace, and developer uptake of Instant Apps was minimal. Even in 2017, loading an app instead of a website had limited utility. As a result, most of us probably only encountered Instant Apps a handful of times in all the years it was an option for developers.

To use the feature, which was delivered to virtually all Android devices by Google Play Services, developers had to create a special “instant” version of their app that was under 15MB. The additional legwork to get an app in front of a subset of new users meant this was always going to be a steep climb, and Google struggles to incentivize developers to adopt new features. Plus, there’s no way to cram in generative AI! So it’s not a shock to see Google retiring the feature.

This feature is currently listed in the collection of Google services in your phone settings as “Google Play Instant.” Unfortunately, there aren’t many examples still available if you’re curious about what Instant Apps were like—the Finnish publisher Ilta-Sanomat is one of the few still offering it. Make sure the settings toggle for Instant Apps is on if you want a little dose of nostalgia.

https://arstechnica.com/gadgets/2025/06/another-one-for-the-graveyard-google-to-kill-instant-apps-in-december/