AI threats in the wild: The current state of prompt injections on the web
2026-07-19T01:23:43Z•057892157fb0c1f23ad4c4f94c5f1ff64a40766c2a616d99d354a32cab00c45b
AI securityAndroidDBSCDNS parserGeminiGoogle WorkspaceIPILLMMerkle Tree CertificatesPLANTSPQCRustbaseband modemcertificate transparencycookie theftdevice bound session credentialsindirect prompt injectioninfostealermemory safetypost-quantum cryptographyprompt injectionquantum-safe HTTPSsession theftvulnerability rewards program
What happened
A set of Google Security Blog posts covering multiple high-priority security initiatives: (1) empirical analysis and mitigation of Indirect Prompt Injection (IPI) on the public web and ongoing hardening of LLM-based products (Workspace/Gemini) against prompt-injection attacks; (2) Pixel modem memory-safety improvements by integrating a Rust-based DNS parser to reduce remote exploitation risk; (3) Device Bound Session Credentials (DBSC) rolling out to prevent cookie/session theft by malware and infostealers; (4) Google VRP’s 2025 year-in-review and continued emphasis on vulnerability research;(
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 057892157fb0c1f23ad4c4f94c5f1ff64a40766c2a616d99d354a32cab00c45b
- Enrichment time
- 2026-07-19T01:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.