AI threats in the wild: The current state of prompt injections on the web
2026-06-22T01:23:44Z•1d1fb0747cdb33211c647163ab2a19ac29ff493348be34d3aa5ad777886119e7
AI threatsAndroid 17DBSCDNS parserGeminiGoogle WorkspaceIPILLM securityLummaC2PQCPixel basebandRustVRPbrowser securitycookie theftdevice-bound session credentialsfirmware hardeningindirect prompt injectioninfostealermemory safetymodem securitypost-quantum cryptographyprompt injectionquantum-safe HTTPS','Merkle Tree Certificates','MTC','PLANTS','Ivulnerability rewards program
What happened
This collection of Google Security Blog posts covers multiple proactive defenses and threat research updates across AI, mobile, web, and cryptography. Key points: Google Threat Intel found real-world activity and growing risk from Indirect Prompt Injection (IPI) targeting LLM-powered apps and Workspace/Gemini, and describes continuous mitigations and monitoring. Chrome and Google Account teams announced Device Bound Session Credentials (DBSC) to prevent stolen browser cookies from being reused by infostealer malware. Pixel team integrated a memory-safe Rust DNS parser into the modem/baseband (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 1d1fb0747cdb33211c647163ab2a19ac29ff493348be34d3aa5ad777886119e7
- Enrichment time
- 2026-06-22T01:23:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.