Desk/2025-W31

Week of Jul 28 – Aug 3, 2025

4 records2 status changes on new evidence4 new findings

What changed in what we know

New findings

Attacks & incidents

Jul 28, 2025
Tracebit shows Gemini CLI could silently run attacker commands when reading untrusted code
AttackVulnerability disclosureTracebit, Google

Tracebit reported that Gemini CLI's default configuration could be led by instructions in a repository file, combined with weak command validation and misleading display, to execute hidden commands after a user had allowlisted a benign one. Google classified it P1/S1 and fixed it in Gemini CLI 0.1.14 on 2025-07-25.

Defense & research

Jul 28, 2025
Large public competition finds all 22 tested frontier agents vulnerable to prompt injection
DefenseBenchmarkGray Swan AI, UK AI Security Institute

Zou and colleagues (Gray Swan and collaborators; Anthropic describes the resulting benchmark as developed with the UK AI Security Institute) report a public red-teaming competition with 1.8 million prompt-injection attacks against 22 frontier agents in 44 deployment scenarios, producing over 60,000 successful policy violations. From these they build the Agent Red Teaming (ART) benchmark and find nearly all agents break within 10 to 100 queries for most behaviors, with high transfer and little correlation between robustness and model size or capability.

Policy & standards

Aug 2, 2025
EU AI Act obligations for general-purpose AI model providers enter into application
PolicyRegulationEuropean Commission

Obligations for providers of general-purpose AI models under the EU AI Act, including systemic-risk duties to evaluate models, mitigate risks, report serious incidents and ensure cybersecurity, entered into application on August 2, 2025. The Commission's enforcement powers apply from August 2, 2026, and models placed on the market before August 2025 must comply by August 2, 2027.