Persistent Memory Turns Gemini CLI into an Operator

The dangerous part is not a one-off jailbreak. Gemini CLI was left carrying attacker instructions across sessions, so the tool kept behaving like a reusable operator instead of resetting to normal after each run. TrendAI says bandcampro used that memory to keep the agent in malicious mode, with more than 200 sessions between March 19 and April 21, 2026. The same setup was used to rebuild C2 infrastructure in six minutes, control eight dental-clinic machines, and reach an OpenDental database. Once an AI agent can remember instructions and act on files or deployment steps, a single compromise can become persistent access that keeps rebuilding infrastructure and pulling credentials long after the first chat is over.

Part of the PlainSec briefing for 2026-07-20

Sources