AI threats in the wild: The current state of prompt injections on the web
Google’s Threat Intelligence teams detected a 32% rise in Indirect Prompt Injection (IPI) attempts on the public web between November 2025 and February 2026, though most attacks remain low-sophisticat…
The threat of indirect prompt injection
Google’s Threat Intelligence teams detected a 32% increase in indirect prompt injection (IPI) attempts on the public web between November 2025 and February 2026, with most attacks being low-sophistica…
The threat of indirect prompt injection
Google’s Threat Intelligence teams found real-world indirect prompt injection (IPI) attempts on the public web, with a 32% increase in malicious detections between November 2025 and February 2026. Mos…
GN Reference
The GN build system reference documentation has been updated to include a new buildfile function, `tool_specify`, which allows developers to define arguments for a toolchain tool. This change affects …
TraitGlobalAllocCopy item path
The Rust programming language’s standard library has introduced the `GlobalAlloc` trait, enabling developers to register a custom memory allocator as the default allocator for Rust programs using the …
Android Rust Toolchain
Google has introduced a Rust toolchain for the Android Open Source Project, enabling developers to build and test Rust code for Android. The toolchain supports multiple architectures and provides preb…
Bringing Rust to the Pixel Baseband
Google has integrated a memory-safe Rust-based DNS parser into the cellular baseband firmware of its Pixel 10 series devices, marking a significant advancement in proactive security for Pixel modems. …
Google Online Security Blog
Google announced two major security advancements: first, the integration of a memory-safe Rust-based DNS parser into the Pixel 10 modem firmware, marking the first use of a memory-safe language in Pix…
Google Online Security Blog: Bringing Rust to the Pixel Baseband
Google has integrated a memory-safe Rust-based DNS parser into the cellular baseband firmware of its Pixel 10 series devices, marking the first use of a memory-safe language in this critical component…
Google Online Security Blog: Bringing Rust to the Pixel Baseband
Google has integrated a memory-safe Rust-based DNS parser into the cellular baseband firmware of its Pixel 10 series devices, marking a significant advancement in proactive security for Pixel modems. …
Protecting Cookies with Device Bound Session Credentials
Google has announced the public availability of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146, with macOS support planned in an upcoming release. DBSC is a security innovatio…
Google Online Security Blog: Protecting Cookies with Device Bound Session Credentials
Google has announced the public availability of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146, with macOS support planned in an upcoming Chrome release. DBSC is a security in…
Search code, repositories, users, issues, pull requests...
The GitHub issue page for the W3C Web Application Security Working Group’s DBSC (Device Bound Session Credentials) project highlights ongoing technical challenges and proposed solutions related to ses…
Google Online Security Blog: Protecting Cookies with Device Bound Session Credentials
Google has introduced Device Bound Session Credentials (DBSC) in Chrome 146 for Windows users, with macOS support planned in an upcoming release, marking a proactive shift in combating session theft. …
Components of Generative AI Systems - SAIF
Google’s SAIF (Secure AI Framework) initiative introduces an extended risk framework specifically addressing the unique security challenges posed by agentic AI systems, which can autonomously take act…
Google Workspace’s continuous approach to mitigating indirect prompt injections
Google has announced a continuous, multi-layered defense strategy to combat indirect prompt injection (IPI) attacks targeting its Workspace with Gemini platform. IPI is a sophisticated threat where at…
Google Online Security Blog: April 2026
Google has significantly enhanced its defenses against indirect prompt injection (IPI) attacks targeting AI applications within Google Workspace with Gemini. The most critical change is the adoption o…
Google Online Security Blog: 2026
Google has significantly advanced its security posture for AI-driven applications, particularly within its Workspace with Gemini ecosystem, by introducing a continuous and multi-layered defense strate…
Google Online Security Blog: Google Workspace’s continuous approach to mitigating indirect prompt injections
Google Workspace has adopted a continuous, multi-layered approach to mitigate indirect prompt injection (IPI) attacks, a growing threat to AI applications like Workspace with Gemini. Unlike static sec…
Google Online Security Blog: Google Workspace’s continuous approach to mitigating indirect prompt injections
Google has announced a continuous, multi-layered approach to mitigating indirect prompt injection (IPI) attacks targeting its Workspace with Gemini platform. IPI is a sophisticated threat where attack…
Track Googleblog on autopilot
- · Weekly AI brief — narrative summary of what shipped, every Monday 9 AM
- · Email or Slack alerts, or chat with the archive in your dashboard
- · Add Googleblog + up to 4 more competitors free, no credit card

