AI threats in the wild: The current state of prompt injections on the web
2026-06-09T13:23:40Z•bcaff4e8a7e3bf9f19da7797139ba14802a1b4453d40610d5736c95787d5b60f
AI securityAndroidCertificate TransparencyChromeDBSCDNS parserGeminiGoogle WorkspaceIPILLM securityMerkle Tree CertificatesPQCPixelRustVRPbasebandcookie theftdevice bound session credentialsindirect prompt injectioninfostealermemory safetypost-quantum cryptographyprompt injectionquantum-safe HTTPSsession hijacking
What happened
A set of Google Security Blog posts covering active threats and platform hardening: Google Threat Intelligence observed real-world indirect prompt injection (IPI) patterns on the public web and highlights IPI as a top priority for LLM/agent security; Google Workspace (with Gemini) is adopting continuous defenses against IPI. Chrome/Google Account teams announced Device Bound Session Credentials (DBSC) to proactively prevent session cookie theft being abused after malware exfiltration. The Pixel team integrated a memory-safe Rust DNS parser into modem firmware to reduce memory-safety risk. The/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- bcaff4e8a7e3bf9f19da7797139ba14802a1b4453d40610d5736c95787d5b60f
- Enrichment time
- 2026-06-09T13:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.