AI threats in the wild: The current state of prompt injections on the web
2026-05-19T13:23:39Z•b68f0539c907fbca36ca8f1a3068da466d445e3b282c124ce17dfb36d936352a
AndroidAndroid 17DBSCDNS parserDevice Bound Session CredentialsGeminiGoogle WorkspaceIPILLM securityLummaC2MTCs","Certificate Transparency","ChromeMerkle Tree CertificatesPQCPixel basebandRustVRPVulnerability Rewards Programcookie theftindirect prompt injectioninfostealermemory-safetymodem securitypost-quantum cryptographyprompt-injectionquantum-safe HTTPS
What happened
A set of Google Security Blog posts covering multiple active security topics: (1) analysis and real-world monitoring of indirect prompt injection (IPI) attacks against LLM-based agents and continuous mitigations (including Google Workspace/Gemini defenses); (2) adoption of Rust for a memory‑safe DNS parser in the Pixel modem/baseband to reduce memory-safety vulnerabilities; (3) public availability rollout of Device Bound Session Credentials (DBSC) in Chrome to prevent cookie/session exfiltration and abuse by infostealer malware (e.g., LummaC2); (4) the Vulnerability Rewards Program (VRP) 2025年
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- b68f0539c907fbca36ca8f1a3068da466d445e3b282c124ce17dfb36d936352a
- Enrichment time
- 2026-05-19T13:23:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.