logo

Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild

ID: d6385a6e-8ac9-5268-bbc3-c458f856935e

STIX ID: report--d6385a6e-8ac9-5268-bbc3-c458f856935e

Feed Name: Palo Alto Networks Unit 42

Threat Score
72/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

Author: Beliz Kaleli, Shehroze Farooqi, Oleksii Starov and Nabeel Mohamed

...
...

This Unit 42 report analyzes web-based indirect prompt injection (IDPI) attacks in which adversaries embed hidden or obfuscated instructions in web content that downstream LLMs or AI agents ingest and execute; it provides a taxonomy of attacker intents and payload engineering techniques, documents multiple real-world detections (ranging from low-severity irrelevant output to critical data destruction and unauthorized transactions), enumerates indicators of compromise (URLs and payment links), and recommends defensive measures for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.