AI threats in the wild: The current state of prompt injections on the web

2026-07-14T01:23:43Zef0244468da148f8c7e263ff0c7f28023eb05e0b7b10a85c11c563016cf7bbbc
Android 17Certificate Transparency (CT)ChromeDBSCDNS parserGeminiGoogle WorkspaceIPILLM securityLummaC2Merkle Tree CertificatesPQCPixel basebandRustVRPcookie theftdevice-bound session credentialsgenerative AIindirect prompt injectioninfostealermemory safetymodem securitypost-quantum cryptographyquantum-safe HTTPSvulnerability rewards program

What happened

A set of Google Security Blog posts (April 2026) covering multiple high-impact defenses and threat observations: 1) Indirect Prompt Injection (IPI) and LLM security — Google Threat Intelligence performed a broad web sweep detecting IPI patterns, highlighted IPI as a top emerging vector, and described continuous mitigations (including Google Workspace/Gemini defenses). 2) Device Bound Session Credentials (DBSC) — DBSC moved to public availability on Windows Chrome 146 (macOS coming), designed to block the use of exfiltrated browser cookies by binding session credentials to device hardware, to対抗

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
ef0244468da148f8c7e263ff0c7f28023eb05e0b7b10a85c11c563016cf7bbbc
Enrichment time
2026-07-14T01:23:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.