Researchers and vendors reported that prompt injection remains a primary security risk for AI systems, with attacks increasingly affecting autonomous agents, multimodal models, and mobile assistants rather than only text chatbots. Google outlined a risk-based framework for evaluating prompt injection in AI applications, emphasizing that exposure depends on factors such as access to external content, tool use, autonomy, and the sensitivity of connected systems. Separately, security research into OpenAI-style operator agents showed how malicious web content can manipulate browsing agents into leaking data, following attacker instructions, or misusing connected capabilities, underscoring that indirect prompts embedded in untrusted content can override user intent.
Newer research extended the threat to multimodal and device-resident assistants. Analysis of the AudioHijack attack described adversarial audio injections hidden in background sound that reportedly achieved 79–96% success rates against 13 audio-language models and, in some cases, triggered unauthorized tool use in commercial voice-agent deployments. A separate assessment of ByteDance's Doubao Phone Assistant found that despite protections such as app authentication, mTLS, TEE-backed keys, and restrictions on sensitive actions, the assistant could still be influenced by malicious on-screen content and GUI race conditions, potentially exposing SMS messages, emails, photos, recordings, banking codes, and other private data stored or displayed on the device.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
A Codeby article summarized the AudioHijack research, emphasizing that transcript-based defenses are insufficient for multimodal systems and arguing that audio prompt injection is an emerging production security issue for voice-enabled AI agents.
DarkNavy published a security analysis concluding Doubao Assistant had comparatively strong built-in protections but remained exposed to prompt injection via on-screen content and GUI TOCTOU risks inherent to screenshot-based automation.
At Black Hat USA 2026, Zenity Labs disclosed 'PleaseFix,' a zero-click attack class against agentic browsers that uses hidden instructions in emails, calendar invites, webpages, and shared content to trigger 'Intent Collision' and hijack the agent. The researchers said the issue affects products including Claude in Chrome, Gemini in Chrome, Perplexity Comet, ChatGPT Atlas, and Copilot Edge, and demonstrated impacts including data exfiltration, account takeover, credential theft, phishing, and fraudulent purchases.
At Black Hat USA 2026, Brave security engineer Artem Chaikin presented research showing prompt injection attacks against Opera's AI browser, Perplexity Comet, and ChatGPT Atlas. He demonstrated bypasses using hidden or disguised webpage content and concluded that layered mitigations can reduce, but not eliminate, risks such as data exfiltration and account takeover.
A blog post documented prompt injection exploit scenarios and defensive considerations for ChatGPT Operator, adding practical discussion of agent prompt injection risks.
Google Security Blog published an analysis of how to estimate risk from prompt injection attacks on AI systems, framing prompt injection as a security problem requiring structured risk evaluation.
Doubao Phone Assistant was launched at the end of 2025 as an AI agent with system-level smartphone control across apps, using cloud inference and GUI automation to execute tasks.
A 2025 arXiv preprint identified as arXiv:2507.05587 described AudioHijack, reporting 79–96% attack success rates against 13 large audio-language models and documenting induced behaviors including prompt leakage, harmful output, and unauthorized tool calls.
After Zenity demonstrated that a malicious calendar invite could drive Perplexity Comet to take over a PC by accessing and writing local files, Perplexity fixed the flaw. The issue was tied to Comet's ability to read and modify local files, which Zenity said enabled rapid compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedarkreading.com
Open sourcedarkreading.com
Open sourcecodeby.net
Open sourcedarknavy.org
Open sourcedarknavy.org
Open sourceembracethered.com
Open sourcesecurity.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.