AI threats in the wild: The current state of prompt injections on the web

2026-07-19T01:23:43Z057892157fb0c1f23ad4c4f94c5f1ff64a40766c2a616d99d354a32cab00c45b
AI securityAndroidDBSCDNS parserGeminiGoogle WorkspaceIPILLMMerkle Tree CertificatesPLANTSPQCRustbaseband modemcertificate transparencycookie theftdevice bound session credentialsindirect prompt injectioninfostealermemory safetypost-quantum cryptographyprompt injectionquantum-safe HTTPSsession theftvulnerability rewards program

What happened

A set of Google Security Blog posts covering multiple high-priority security initiatives: (1) empirical analysis and mitigation of Indirect Prompt Injection (IPI) on the public web and ongoing hardening of LLM-based products (Workspace/Gemini) against prompt-injection attacks; (2) Pixel modem memory-safety improvements by integrating a Rust-based DNS parser to reduce remote exploitation risk; (3) Device Bound Session Credentials (DBSC) rolling out to prevent cookie/session theft by malware and infostealers; (4) Google VRP’s 2025 year-in-review and continued emphasis on vulnerability research;(

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
057892157fb0c1f23ad4c4f94c5f1ff64a40766c2a616d99d354a32cab00c45b
Enrichment time
2026-07-19T01:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · AI threats in the wild: The current state of prompt injections on the web · Baitaphish