"security" means many different things. "Security" in the sense of e2ee – sure, that's fraught with e-mail.
But when we're talking "AI agents", that's a whole other level. First zero-click prompt injection attack against an AI agent integrated with e-mail has already been found:
https://fortune.com/2025/06/11/microsoft-copilot-vulnerability-ai-agents-echoleak-hacking/
It just happened to hit Copilot, not Gemini. So far.
Sebastian (npub15m2…gezc) xlenka (npub1f78…2vp5) 🦜 Drew DeVault's blog (npub1qnu…tgsk)