AI threats in the wild: The current state of prompt injections on the web
2026-08-05T13:23:33Z•98713907d78b2982219ccc3f9f92b65aa8b1271cca31bee2b75f036c9c4180e9
AI securityAndroid securityCertificate TransparencyChromeDNS parserDevice Bound Session CredentialsGoogle WorkspaceHTTPSLLM securityLummaC2PQCPixel modemRustTLSagent securitybaseband securitybug bountycookie theftindirect prompt injectioninfostealermemory safetypost-quantum cryptographyremote code executionsession hijackingvulnerability disclosure
What happened
Google Security Blog coverage highlights active and emerging security concerns including indirect prompt injection against AI agents and Workspace integrations, browser session-cookie theft and defenses using Device Bound Session Credentials, memory-safety risks in cellular modem firmware, post-quantum cryptography migration for Android and HTTPS, and ongoing vulnerability research through Google’s VRP. The material is primarily defensive and strategic, but prompt injection, credential theft, and remotely exploitable modem vulnerabilities represent significant threat areas.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- 98713907d78b2982219ccc3f9f92b65aa8b1271cca31bee2b75f036c9c4180e9
- Enrichment time
- 2026-08-05T13:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.