AI threats in the wild: The current state of prompt injections on the web
2026-08-30T19:23:33Z•5174ed00a3170fb151a3af2c320c55717eb9ef40e3703b213ddbb9261da19093
AI agentsAI securityAndroidCertificate TransparencyChromeDNS parserDevice Bound Session CredentialsGoogle Workspace GeminiLLM securityLummaC2PQCPixel modemRustbaseband securitycookie theftindirect prompt injectioninfostealer malwarememory safetypost-quantum cryptographyprompt injectionquantum-safe HTTPSremote code executionsession theftvulnerability rewards
What happened
Google Security Blog posts covering active indirect prompt-injection threats against AI agents and Workspace Gemini, browser session-cookie theft defenses through Device Bound Session Credentials, memory-safety hardening of Pixel modem DNS parsing with Rust, vulnerability-reward activity, and Android/Chrome preparations for post-quantum cryptography. The most immediate security themes are AI-agent manipulation and credential/session theft; the remaining posts describe proactive hardening and cryptographic migration rather than specific vulnerabilities.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 5174ed00a3170fb151a3af2c320c55717eb9ef40e3703b213ddbb9261da19093
- Enrichment time
- 2026-08-30T19:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.