Gemini CLI CVSS 10.0 flaw in versions below 0.39.1 enabled RCE in CI workflows, forcing Google to mandate explicit workspace ...
Researchers say the campaign targeted developer credentials and cloud secrets while abusing trusted publishing and AI coding ...