Threat researchers and security experts reported that indirect prompt injection (IDPI) is being actively used in the wild to manipulate AI agents by embedding hidden instructions in otherwise normal-looking web content (e.g., HTML, metadata, comments, or invisible text). Reported impacts include coercing agents into leaking sensitive data, executing unauthorized actions (including server-side commands), and manipulating downstream systems such as AI-based ad review and search ranking workflows (e.g., SEO poisoning and phishing promotion), indicating the technique has moved from theoretical to operational abuse.
Separate testing of a healthcare AI used in a prescription-management context showed how prompt injection can bypass safeguards to reveal system prompts, generate harmful content, and—via persistence mechanisms such as SOAP notes—introduce longer-lived manipulations that could influence clinical outputs (e.g., altering suggested dosages) before human approval. Other items in the set were primarily business/consumer AI commentary (data-management investment surveys, bot-ecosystem interview, and general “dark side of AI” discussion) and did not materially add incident-level or technical detail about prompt-injection exploitation beyond broad risk framing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Unit 42 cited the first known real-world case of indirect prompt injection being used to bypass an AI-based advertisement review system. The broader research also linked the technique to SEO poisoning, attempted unauthorized financial actions, sensitive data exposure, and destructive server-side commands.
Palo Alto Networks' Unit 42 reported that indirect prompt injection attacks were being observed in real-world environments at scale. The researchers documented 22 payload-construction techniques and described attacker methods for hiding malicious instructions in ordinary-looking web content processed by AI tools.
Doctronic and the Utah pilot program said controlled substances cannot be refilled in the current trial and stated that additional safeguards are in place. Their response addressed the reported prompt-injection findings affecting the healthcare AI system.
In a safety-impacting demonstration, researchers showed the AI could be tricked into changing a prescription recommendation, including tripling an OxyContin dosage for later human review. The finding highlighted the potential for prompt injection to influence clinical decision support workflows.
Security researchers reported that Doctronic's prescription-management healthcare AI could be manipulated to reveal system prompts and accept unauthorized instruction changes. They showed both session-limited prompt injection and a persistence method using SOAP notes in clinical records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.