AI threats in the wild: The current state of prompt injections on the web
2026-08-26T01:23:34Z•eae43e83b3225deb78c6ae935a6a3c99b23f7e194b76159e216d65eb57dec107
AI agentsAI securityAndroidCertificate TransparencyChromeDNS parserGeminiGoogle WorkspaceLLM securityLummaC2Merkle Tree CertificatesPQCPixel modemRustTLScellular basebandcookie theftdevice-bound session credentialsindirect prompt injectioninfostealermemory safetypost-quantum cryptographyquantum-safe HTTPSsession theftvulnerability disclosure
What happened
Google Security Blog entries describe current security priorities and defensive initiatives, including real-world indirect prompt injection against AI agents and Workspace Gemini, memory-safe Rust adoption in Pixel modem DNS parsing, device-bound session credentials to prevent stolen-cookie abuse, Android post-quantum cryptography migration, and quantum-safe HTTPS certificate research. The collection is primarily strategic and mitigative; it does not disclose specific exploitable vulnerabilities or assigned CVEs.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- eae43e83b3225deb78c6ae935a6a3c99b23f7e194b76159e216d65eb57dec107
- Enrichment time
- 2026-08-26T01:23:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.