The Google Online Security Blog recently published an article titled "AI threats in the wild: The current state of prompt injections on the web," which provides a detailed analysis of indirect prompt injection (IPI) attacks. Here are the key points from the article:
-
Current State of IPI Attacks:
- While past attempts at IPI attacks were low in sophistication, there is an upward trend indicating growing interest.
- The observed activity suggests limited sophistication but shows signs of increasing over time.
-
Scope and Methodology:
- The study focused on scanning CommonCrawl, which covers the public web but excludes major social media sites.
- There was a 32% relative increase in malicious IPI detections between November 2025 and February 2026.
-
Types of IPI Attacks Observed:
- Experiments and Pranks: Many website authors were running experiments or pranks without replicating advanced strategies.
- Data Exfiltration: A small number of prompt injections aimed at theft of data, but sophistication was low.
- Destruction: Some websites attempted to vandalize the machine of anyone using AI assistants with simple commands like deleting files
Read the full article at Malware Analysis, News and Indicators - Latest topics
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





