Security researchers reported that prompt injection is enabling practical attacks against agentic AI systems that have access to tools and user data, and argued the industry is underestimating the threat. A proposed framing, “promptware,” describes malicious prompts as a malware-like execution mechanism that can drive an LLM to take actions via its connected tools—potentially leading to data exfiltration, cross-system propagation, IoT manipulation, or even arbitrary code execution, depending on the permissions and integrations available.
Trail of Bits disclosed results from an adversarial security assessment of Perplexity’s Comet browser, showing how prompt injection techniques could be used to extract private information from authenticated sessions (e.g., Gmail) by abusing the browser’s AI assistant and its tool access (such as reading page content, using browsing history, and interacting with the browser). Their threat-model-driven testing emphasized that agentic assistants can treat external web content as instructions unless it is explicitly handled as untrusted input, and they published recommendations intended to reduce prompt-injection-driven data paths between the user’s local trust zone (profiles/cookies/history) and vendor-hosted agent/chat services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Following LayerX's BioShocking disclosure, OpenAI reportedly patched the issue in ChatGPT Atlas and Genspark later told SC Media it had fixed the problem. Anthropic's attempted fix for its Chrome plugin was reportedly ineffective at the time of reporting, while Perplexity closed the report without a fix and Fellou and Sigma Browser initially did not respond.
LayerX disclosed a prompt-injection technique called BioShocking that manipulates AI-powered browsers and agentic browsing tools into accepting false contextual rules and leaking sensitive data. The researchers demonstrated credential exfiltration from a private GitHub repository and said multiple AI-enabled browsing products were affected, with mixed vendor responses.
After the assessment, Trail of Bits published five recommendations for teams building AI agents, including ML-centered threat modeling, strict trust boundaries between system instructions and external content, systematic prompt-injection red-teaming, least-privilege tool access, and treating AI inputs as untrusted data. The write-up also noted that one exploit variant depended on misspellings in a fake warning to bypass fraud detection.
During the assessment, Trail of Bits built multiple proof-of-concept exploits showing that Comet could be induced to exfiltrate private Gmail content from an authenticated user session to attacker-controlled infrastructure when asked to summarize a page. The researchers identified four prompt injection techniques and showed multi-step attack flows using redirects, fragment collection, and social-engineering lures such as CAPTCHAs and fake system warnings.
Before Comet's launch, Trail of Bits performed an adversarial security assessment of Perplexity's LLM-powered browser assistant using its TRAIL threat-modeling approach. The review focused on how prompt injection delivered through attacker-controlled web pages could affect the agentic browsing assistant.
The paper introduced a seven-stage kill chain for promptware, distinguishing prompt injection from jailbreaking and describing how attacks can progress to data exfiltration, lateral movement, IoT manipulation, or code execution depending on connected tools and permissions. It also highlighted persistence mechanisms through poisoned retrieved content and long-term memory features.
A research paper by authors from Tel Aviv University, Ben-Gurion University of the Negev, and Harvard University reviewed 36 real-world attacks over a three-year period and found that prompt injection incidents were becoming more sophisticated. The authors argued these attacks should be treated as a distinct malware class, which they call "promptware."
According to the report, Roy Paz notified six affected AI browser and plugin vendors about the BioShocking prompt-injection issue in October 2025. The disclosures covered products including ChatGPT Atlas, Comet, Fellou, Genspark Browser, Sigma Browser, and the Claude Chrome extension.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityweek.com
Open sourcexakep.ru
Open sourcemalwarebytes.com
Open sourcescworld.com
Open sourcearstechnica.com
Open sourcecybersecuritynews.com
Open sourceblog.trailofbits.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.