AI threats in the wild: The current state of prompt injections on the web

2026-05-08T01:23:44Zfcb774e53999a70828be20749570b0ffcc2cc41b94e247a18c0ab8040d912830
AI-securityAndroidDBSCLLMLummaC2MTCMerkle-tree-certificatesPQCRustVRPcertificate-transparencycookie-theftdevice-bound-session-credentialsgoogle-workspaceindirect-prompt-injectioninfostealermemory-safetymodem-securitypixel-basebandpost-quantum-cryptographyprompt-injectionvulnerability-rewards-program

What happened

This collection of Google Security Blog posts highlights multiple active and emerging threats and Google’s mitigations: researchers observed real-world indirect prompt injection (IPI) patterns on the public web and call IPI a top priority for AI/LLM security, with Workspace receiving continuous defenses against IPI. Chrome is rolling out Device Bound Session Credentials (DBSC) to prevent cookie-theft-based account takeover from infostealer malware (e.g., LummaC2). Pixel modem firmware is being hardened by integrating a memory-safe Rust DNS parser to reduce widespread modem memory-safety bugs,,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
google_security_blog
Record identifier
fcb774e53999a70828be20749570b0ffcc2cc41b94e247a18c0ab8040d912830
Enrichment time
2026-05-08T01:23:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.