AI threats in the wild: The current state of prompt injections on the web
2026-08-04T13:23:35Z•331b4c8272c38505e2dd2b7c9b658878373676ba81c94e26c2d537a0925debd1
AI-agentsAI-securityAndroid-securityChromeDNS-parserDevice-Bound-Session-CredentialsGeminiGoogle-WorkspaceHTTPS-securityLLM-securityLummaC2PQCRustaccount-takeoverbaseband-securitybrowser-securitycredential-theftindirect-prompt-injectioninfostealermemory-safetymodem-securitypost-quantum-cryptographyprompt-injectionremote-code-executionsession-cookie-theft
What happened
Google Security Blog items cover active and emerging security issues, including real-world indirect prompt injection against AI agents and Workspace Gemini, session-cookie theft by infostealers and Chrome’s Device Bound Session Credentials defense, modem memory-safety hardening with Rust, post-quantum cryptography migration for Android and HTTPS, and Google’s vulnerability rewards program. The most immediate threat themes are AI-agent manipulation and account takeover through stolen browser cookies; no specific CVEs are identified in the supplied content.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 331b4c8272c38505e2dd2b7c9b658878373676ba81c94e26c2d537a0925debd1
- Enrichment time
- 2026-08-04T13:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.