惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
S
Security @ Cisco Blogs
月光博客
月光博客
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Cisco Talos Blog
Cisco Talos Blog
J
Java Code Geeks
Scott Helme
Scott Helme
S
Schneier on Security
腾讯CDC
博客园 - 司徒正美
L
Lohrmann on Cybersecurity
Latest news
Latest news
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
有赞技术团队
有赞技术团队
AWS News Blog
AWS News Blog
V
Visual Studio Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Hugging Face - Blog
Hugging Face - Blog
爱范儿
爱范儿
小众软件
小众软件
博客园 - Franky
Attack and Defense Labs
Attack and Defense Labs
美团技术团队
IT之家
IT之家
TaoSecurity Blog
TaoSecurity Blog
SecWiki News
SecWiki News
P
Proofpoint News Feed
阮一峰的网络日志
阮一峰的网络日志
博客园_首页
PCI Perspectives
PCI Perspectives
量子位
T
Threat Research - Cisco Blogs
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
Cyberwarzone
Cyberwarzone
The Cloudflare Blog
博客园 - 三生石上(FineUI控件)
L
LINUX DO - 最新话题
Forbes - Security
Forbes - Security
罗磊的独立博客
宝玉的分享
宝玉的分享
Simon Willison's Weblog
Simon Willison's Weblog
雷峰网
雷峰网
www.infosecurity-magazine.com
www.infosecurity-magazine.com
人人都是产品经理
人人都是产品经理
N
News and Events Feed by Topic

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
‘Significant Threat’—Billions Of Gmail Users At Risk From Google Security Gaffe
Davey Winder · 2026-05-11 · via Forbes - Innovation
Gmail logo on smartphone, with Google logo displayed in the background of image.

Google security flaw is a significant threat to nearly all Gmail users.

CFOTO/Future Publishing via Getty Images

Updated May 12: This article, originally published May 11, which revealed a critical flaw in the integration between Gmail and Google Drive that poses a significant security threat to nearly everyone who uses a Gmail account, has now been updated to include details of a second security discrepancy uncovered by the same researcher, this time concerning a circumvention of Google Drive’s dangerous files protection warnings. Here’s everything you need to know about both security issues, along with advice on how billions of Gmail users can stay safe.

According to Blake Barnes, Google’s own vice president of product for Gmail, “3 billion users rely on Gmail to connect and get things done,” while Google Drive has an estimated one billion active users. I can exclusively reveal that an architectural flaw in the integration between the two services poses a significant security threat to “nearly every individual with a Gmail account.” A new report has confirmed, with a proof of concept, that attackers can leverage Gmail and Google Drive as a high-trust malware delivery infrastructure by delivering malicious attachments that receive a misleading and dangerous “scanned by Gmail” seal of approval. Here’s everything you need to know, including the response from Google itself.

ForbesGoogle Play ‘Call History For Any Phone Number’ Scam Cons Millions

Scanned By Gmail Doesn’t Provide The Attachment Security You Might Think It Does

The most popular free web service on the planet, Gmail, has a lot of security positives. And, oh boy, does it need them as it is under persistent attack from hackers and scammers alike. Thankfully, both Gmail and Google Drive have mechanisms in place to prevent them from being used to distribute the type of malicious files often used in such attacks. However, as Ben Ilkashi, a security researcher at Pentera Labs, exclusively shared with me, it is possible for an attacker to exploit these to devastating effect. “What if I told you that you could trick a machine into displaying your malicious attachment as completely safe?” Ilkashi said. “What if I told you that you could get Google itself to sign off on your phishing payload and effectively achieve the holy grail of phishing attacks?” That grail is absolute and unquestioned credibility. Trust on steroids, if you like.

Ilkashi’s research, now published by Pentera Labs following a 90-day responsible disclosure period, has highlighted an architectural misalignment within Google’s unified security framework that enables malware that is “otherwise explicitly blocked by Gmail’s attachments scanner” to be hosted on Drive and delivered to recipients alongside a “Scanned by Gmail” label of trust. First reported through the Google Bug Hunters program on December 14, 2025, Google confirmed that it was a duplicate of an “internally tracked issue.” On January 22, Google’s Trust and Safety unit confirmed that “no fix timeline was available,” according to Ilkashi, and the decision regarding disclosure timing was up to Pentera Labs.

ForbesCritical New Google Update—127 Chrome Security Vulnerabilities ConfirmedBy Davey Winder

Google’s Serious Gmail And Drive Security Gaffe Explained

This serious Google security gaffe came to light when Ilkashi was initially researching the malicious use of Scalable Vector Graphics as a phishing campaign payload. “As part of my payloads testing against popular providers,” Ilkashi explained, “I encountered an attachment block in Gmail.’ This was accompanied by a ‘virus detected’ label when attaching the file, and Gmail prevented the payload from being sent. Google Drive also has a scanning mechanism marking malicious files as ‘Flagged for abuse’ and preventing anyone aside from the author from being able to download them, alongside a warning interstitial that alerts users before downloading potentially harmful file types. That’s the good news, and you know what’s coming next, don’t you?

The bad news is that Ilkashi was able to send a malicious SVG sample, already flagged by Gmail as ‘virus detected’ and blocked from being sent as a result, by using Google Drive as a hosting platform. “Contrary to Gmail’s detection,” Ilkashi explained, “Google Drive did not classify this file as malicious.” Yes, you read that right: despite already being flagged as a virus, Gmail’s own Drive attachments feature allowed it to be uploaded to Drive and configured to be accessible to anyone possessing the share link. This is an architectural misalignment between the scanning mechanisms, and it’s something that poses a danger to almost all users of Gmail as a result. A new email could be composed, including a now-known-to-be-malicious file link from Drive, but Gmail did not scan it again and instead just sent it as if nothing was wrong. Complete with a misleading scanned by Gmail label.

Do not trust the 'Scanned by Gmail' assurance.

Pentera Labs

The issue appears to be that Gmail grants implicit trust to files that originate from Google Drive, assuming that because it is within the internal ecosystem other is pre-vetted and, as such, Gmail then bypasses its standard verification steps “allowing the malicious payload to inherit the 'safe' status of its storage
container,” Ilkishi said.

Google Drive’s Incomplete Scan Warning Circumvention For ‘Blocked By Gmail’ File

Amazingly, considering that this is the first published research report from Ilkashi, he managed to find not one but two problems that are worthy of serious attention. Explaining that his curiosity, having discovered the “Scanned by Gmail” vulnerability, had peaked and led to the pondering of whether other issues existed within the Google Drive and Gmail service integration, Ilkashi wondered “what would happen if a payload was not detected as a virus by Gmail.” It’s worth a little bit of background here, in that an executable not detected as a virus is “Blocked for security reasons” in Gmail, with Google stating that a recipient can ask the sender to upload the file to Drive “if you’re sure it is safe” and then “send it as a Drive attachment.”

Ilkashi said this got him thinking about what would happen if Google Drive couldn’t label your malware as “Flagged for abuse” after an incomplete scan, for example. Drive will then display another warning pop-up stating it cannot be scanned for viruses or that the file type might be dangerous, and offering an option to download it anyway. “This warning message is crucial because it indicates an incomplete scan of the file by Google,” Ilkashi said, “a circumstance that significantly increases the user's risk upon downloading and executing it.” But what if that warning could be bypassed?

Here we go again. A malicious sample was created that wasn’t recognized as known malware by either Gmail or Drive. The sample was duly labeled by Gmail as “Blocked for security reasons” rather than Virus detected”, but when uploaded to Drive was not labeled as “Flagged for abuse,” Ilkashi reported. So he then attached the share link to an email and sent it, only for this to once again be “ presented as an attachment,” and accompanied by the "Scanned by Gmail" label. The expected warning was completely missing, and Ilkashi said that he could “download the file in Gmail’s endpoint (mail.google.com) directly from the email and from the file preview, without any warning page or popup.” Opening the link itself, and Athen attempting to download the file from Drive directly, however, did display the expected warning screen.

Ilkashi concluded that this represented a flaw within the implementation of the Google Drive file download mechanism within Gmail’s endpoint, ultimately enabling unwary users to download files that had not been appropriately scanned and without triggering Google’s safety warnings. “This finding reinforces the fact that Gmail’s and Drive’s file handling mechanisms are not aligned,” Ilkashi warned, “This misalignment allows attackers to identify gaps, such as those presented in this article, and exploit them so that Google’s services effectively serve as a convincing and trustworthy delivery infrastructure.”

Google Responds To Gmail Attachment Security Disclosure

“We have demonstrated two distinct logic flaws,” Ilkashi said, “each undermining a different security mechanism, suggesting that further security issues can possibly arise, due to the inherent complexity and the implicit trust in the integrated
architecture of Google Workspace services.”

I reached out to Google, and a spokesperson provided the following statement: "Protecting Google Workspace users is our top priority. Gmail and Google Drive automatically block the vast majority of malicious files—including dangerous executable attachments—before they can ever reach an inbox." However, as the Pentera Labs research, along with a fully working proof of concept, shows, this simply isn’t good enough when attackers are able to exploit user trust and disguise malicious payloads behind the “Scanned by Gmail’ facade of legitimacy.

ForbesMy Password Has Been Stolen—What Happens Next?By Davey Winder

Google has said it is actively updating the user interface to clarify how safety checks are displayed when files are shared via Google Drive links, giving users a clear and accurate security context at all times. Google also said that Gmail’s “built-in defenses successfully prevent users from sending or receiving dangerous file types, such as executables, as direct email attachments,” stating that “this fundamental security boundary has not changed and remains fully operational.”

Google told me that Gmail proactively displays prominent, red warning banners to alert users if they receive a message containing a link that is later determined to point to a potentially suspicious or un-scanned file. Furthermore, while Google Drive allows users to upload files to their personal storage, it employs robust automated scanning to detect malware and block users from downloading or sharing infected files to prevent device compromise. Google also reiterated that it regularly works with the broader cybersecurity research community to identify opportunities to refine its protections and is appreciative of their contributions to a secure ecosystem.

Which is great, apart from the fact that the issue as outlined by Ilkashi and Pentera Labs remains exploitable. The proof of concept is valid, and I have seen this in action myself, it utilized a crafted ransomware executable that employs an xor-based encryption as a payload. “For the purpose of this demonstration,” Ilkashi said, “the ransomware will search and encrypt a file called encrypt-me.txt in the same directory. However, this could be easily modified to initiate an infinite end-to-end attack vector, utilizing Google's products as a credible delivery mechanism.”

This “is not an isolated or theoretical edge case, but a reproducible architectural gap,” Ilkishi warned, adding that if it can be discovered through security analysis, “it can also be identified and leveraged by motivated adversaries.” Until Google addresses this security flaw, all Gmail users are advised to treat emails containing Google Drive links or attachments as potentially dangerous, regardless of any “Scanned by Gmail” label.