AI threats in the wild: The current state of prompt injections on the web
2026-08-29T19:23:33Z•21b85e2486914765aaf3252bd3ba90a4bc651163670ec534d3de7312e0243c2f
AI-securityAndroidCertificate-TransparencyChromeDNS-parserDevice-Bound-Session-CredentialsGeminiGoogle-WorkspaceHTTPSLLM-securityLummaC2PixelRustagent-securitycellular-basebandindirect-prompt-injectioninfostealersmemory-safetypost-quantum-cryptographysession-cookie-theftvulnerability-rewards
What happened
Google Security Blog entries covering active indirect prompt injection threats against AI agents and Workspace Gemini, defenses against browser session-cookie theft through Device Bound Session Credentials, memory-safe Rust adoption in Pixel modem firmware, Android and Chrome post-quantum cryptography initiatives, and the 2025 vulnerability rewards program review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 21b85e2486914765aaf3252bd3ba90a4bc651163670ec534d3de7312e0243c2f
- Enrichment time
- 2026-08-29T19:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.