AI threats in the wild: The current state of prompt injections on the web
2026-07-18T01:23:40Z•72b102db9bad3b3151194ff3e7cdf23447a879adc92ddc57b73f23de7fdd0335
AI safetyAndroidAndroid 17Certificate TransparencyDBSCDNS parserGeminiIPILLM securityLummaC2Merkle Tree CertificatesPLANTSPQCRustVulnerability Rewards Program (VRP)Workspacebaseband modemcookie theftdevice bound session credentialsindirect prompt injectioninfostealermemory safetypost-quantum cryptographyprompt injectionquantum-safe HTTPS
What happened
A set of Google Security Blog posts (Mar–Apr 2026) covering emerging AI and platform threats and mitigations. Google Threat Intelligence highlights indirect prompt injection (IPI) as a top attack vector and reports active monitoring of the public web for IPI patterns, while Workspace and Gemini receive continuous defenses to harden LLMs and agentic workflows. Chrome and Google publish multiple platform hardening measures: Device Bound Session Credentials (DBSC) to proactively prevent cookie/session theft from infostealers, adoption of a Rust DNS parser in Pixel baseband firmware to reduce mem‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 72b102db9bad3b3151194ff3e7cdf23447a879adc92ddc57b73f23de7fdd0335
- Enrichment time
- 2026-07-18T01:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.