AI threats in the wild: The current state of prompt injections on the web
2026-08-08T01:23:33Z•2d2c3f95b1de3672ee42462ea61b6506e8a0d593414044afb06c1b698d6bc6ac
AI agentsAI securityAndroidCertificate TransparencyChromeDNS parserDevice Bound Session CredentialsGoogle WorkspaceHTTPSLLM securityLummaC2Merkle Tree CertificatesPQCPixel modemRustTLScellular basebandcookie theftindirect prompt injectioninfostealer malwarememory safetypost-quantum cryptographyremote code executionsession theft
What happened
Google security research highlights active and emerging threats across AI systems, browser session security, cellular modem firmware, and cryptographic infrastructure. Key topics include real-world indirect prompt injection against AI agents and Workspace integrations, device-bound session credentials to prevent stolen-cookie abuse, memory-safe Rust adoption in Pixel modem DNS parsing, and migration toward post-quantum cryptography for Android and HTTPS. These are defensive research and product security initiatives rather than disclosures of a specific exploitable vulnerability.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 2d2c3f95b1de3672ee42462ea61b6506e8a0d593414044afb06c1b698d6bc6ac
- Enrichment time
- 2026-08-08T01:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.