AI threats in the wild: The current state of prompt injections on the web
2026-05-23T01:23:40Z•0ca0bd8bebed2f5bbdd3e214e343212c76a2adeb5319a69986ad29c50f279cb3
AI adversarial attacksAndroid 17DBSCDNS parserGeminiGoogle WorkspaceIPILLM securityLummaC2Merkle Tree CertificatesPLANTSPQCPixel basebandRustVRPcookie theftdevice bound session credentialsindirect prompt injectioninfostealermemory safetymodem securitypost-quantum cryptographyprompt injectionquantum-safe HTTPSvulnerability rewards program
What happened
A set of Google Security Blog posts (Mar–Apr 2026) covering active and emerging threats and defensive work: Google threat teams detected real-world indirect prompt injection (IPI) patterns on the public web and emphasize IPI as an evolving, high-priority attack vector against LLM-enabled agents (including Workspace/Gemini). Google describes continuous mitigations for IPI in Workspace, advances to protect session cookies via Device Bound Session Credentials (DBSC) to prevent cookie/theft abuse by infostealers, and Pixel modem hardening by integrating a Rust-based DNS parser to reduce memory-saf
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 0ca0bd8bebed2f5bbdd3e214e343212c76a2adeb5319a69986ad29c50f279cb3
- Enrichment time
- 2026-05-23T01:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.