AI threats in the wild: The current state of prompt injections on the web
2026-05-04T13:23:46Z•ade32505443038513a2275c5638ce97ceaa45a29a794e57858df3ea86f257af6
AI securityAndroid 17Certificate TransparencyDBSCDNS parserDevice Bound Session CredentialsGeminiGoogle WorkspaceLLM securityLummaC2Merkle Tree CertificatesPLANTSPQCPixel basebandRustVRPVulnerability Rewards Programcookie theftindirect prompt injectioninfostealermemory safetymodem securitypost-quantum cryptographyprompt injectionquantum-safe HTTPS
What happened
A Google Security Blog roundup covering multiple product- and industry-level defenses: research and real-world monitoring show Indirect Prompt Injection (IPI) is an active and prioritized threat to AI/LLM-based systems, and Google is continuously hardening Workspace/Gemini against IPI. Chrome is rolling out Device Bound Session Credentials (DBSC) to proactively prevent cookie/session theft from infostealer malware. Pixel firmware work replaces unsafe modem DNS parsing with a Rust implementation to reduce memory-safety vulnerabilities. Google published its VRP 2025 review, and announced Android
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- ade32505443038513a2275c5638ce97ceaa45a29a794e57858df3ea86f257af6
- Enrichment time
- 2026-05-04T13:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.