Indirect prompt injection moves from demo to in-the-wild attacks
Researchers documented the first large-scale indirect prompt-injection campaigns, hiding instructions inside content that agents ingest. The durable fix is isolating the 'lethal trifecta' of private data, untrusted content and an outbound channel.