AI threats in the wild: The current state of prompt injections on the web
2026-07-14T01:23:43Z•ef0244468da148f8c7e263ff0c7f28023eb05e0b7b10a85c11c563016cf7bbbc
Android 17Certificate Transparency (CT)ChromeDBSCDNS parserGeminiGoogle WorkspaceIPILLM securityLummaC2Merkle Tree CertificatesPQCPixel basebandRustVRPcookie theftdevice-bound session credentialsgenerative AIindirect prompt injectioninfostealermemory safetymodem securitypost-quantum cryptographyquantum-safe HTTPSvulnerability rewards program
What happened
A set of Google Security Blog posts (April 2026) covering multiple high-impact defenses and threat observations: 1) Indirect Prompt Injection (IPI) and LLM security — Google Threat Intelligence performed a broad web sweep detecting IPI patterns, highlighted IPI as a top emerging vector, and described continuous mitigations (including Google Workspace/Gemini defenses). 2) Device Bound Session Credentials (DBSC) — DBSC moved to public availability on Windows Chrome 146 (macOS coming), designed to block the use of exfiltrated browser cookies by binding session credentials to device hardware, to対抗
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- google_security_blog
- Record identifier
- ef0244468da148f8c7e263ff0c7f28023eb05e0b7b10a85c11c563016cf7bbbc
- Enrichment time
- 2026-07-14T01:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.