AI · 141 days ago
Web content can now act as an instruction channel for AI agents. The standard response is to treat prompt injection as a chat problem, but these payloads matter because they can drive real actions when the agent has access to email, terminals, payments, or other transactional tools.
Forcepoint found 10 active indirect prompt injection payloads in the wild. The payloads were built to trigger fraud, data destruction, API-key theft, content suppression, and attribution hijacking across agents that browse pages, summarize content, index for RAG, or process metadata and comments.
The risk is not the prompt itself. It is the agent’s privilege set. A read-only summarizer is low impact; an agent that can act on behalf of a user can turn poisoned web content into a live compromise path.
3 sources covering this story
Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google
The tech giant found that many indirect prompt injection attempts are harmless, but some malicious exploits have also been identified.
Indirect prompt injection is taking hold in the wild - Help Net Security
Google and Forcepoint researchers searched for indirect prompt injection attacks mounted by attackers in the wild.
Researchers Uncover 10 In-the-Wild Indirect Prompt Injection Attacks
Forcepoint has found 10 new indirect prompt injection payloads targeting AI agents
Part of the PlainSec briefing for 2026-04-28