Researchers and vendors reported that prompt injection remains a primary security risk for AI systems, with attacks increasingly affecting autonomous agents, multimodal models, and mobile assistants rather than only text chatbots. Google outlined a risk-based framework for evaluating prompt injection in AI applications, emphasizing that exposure depends on factors such as access to external content, tool use, autonomy, and the sensitivity of connected systems. Separately, security research into OpenAI-style operator agents showed how malicious web content can manipulate browsing agents into leaking data, following attacker instructions, or misusing connected capabilities, underscoring that indirect prompts embedded in untrusted content can override user intent.
Newer research extended the threat to multimodal and device-resident assistants. Analysis of the AudioHijack attack described adversarial audio injections hidden in background sound that reportedly achieved 79–96% success rates against 13 audio-language models and, in some cases, triggered unauthorized tool use in commercial voice-agent deployments. A separate assessment of ByteDance's Doubao Phone Assistant found that despite protections such as app authentication, mTLS, TEE-backed keys, and restrictions on sensitive actions, the assistant could still be influenced by malicious on-screen content and GUI race conditions, potentially exposing SMS messages, emails, photos, recordings, banking codes, and other private data stored or displayed on the device.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A Codeby article summarized the AudioHijack research, emphasizing that transcript-based defenses are insufficient for multimodal systems and arguing that audio prompt injection is an emerging production security issue for voice-enabled AI agents.
DarkNavy published a security analysis concluding Doubao Assistant had comparatively strong built-in protections but remained exposed to prompt injection via on-screen content and GUI TOCTOU risks inherent to screenshot-based automation.
A blog post documented prompt injection exploit scenarios and defensive considerations for ChatGPT Operator, adding practical discussion of agent prompt injection risks.
Google Security Blog published an analysis of how to estimate risk from prompt injection attacks on AI systems, framing prompt injection as a security problem requiring structured risk evaluation.
Doubao Phone Assistant was launched at the end of 2025 as an AI agent with system-level smartphone control across apps, using cloud inference and GUI automation to execute tasks.
A 2025 arXiv preprint identified as arXiv:2507.05587 described AudioHijack, reporting 79–96% attack success rates against 13 large audio-language models and documenting induced behaviors including prompt leakage, harmful output, and unauthorized tool calls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
codeby.net
Open sourcedarknavy.org
Open sourceembracethered.com
Open sourcesecurity.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.