#Promptware
念のためにいうとキルチェーン(kill chain)ってのは元々軍事用語で敵軍の構造(チェーン)を断ち切ることで自軍を守る先制処置の考え方。これをソフトウェアに応用したのがソフトウェア・キルチェーンで、攻撃のプロセスを7段階に分類し、多層防衛を行うというもの。

ちなみにこれを AI サービスへの攻撃に対する多層防衛に応用したのがが「プロンプトウェア・キルチェーン」で Bruce Schneier 等によって提唱されている。というのを以前記事にした
https://text.baldanders.info/remark/2026/02/the-promptware-kill-chain/
「プロンプトウェア・キルチェーン」
複数のレイヤできっちり仕事をされる Bruce Schneier 先生マジすげーなと思ったのであった。
text.baldanders.info
September 19, 2026 at 6:32 PM
#promptware ?

For realises?

Sounds like someone read too many #potatopunk stories...

...sounds bad if tru...tell me it ain't so !

#infosec #aisecurity
August 25, 2026 at 8:04 PM
Hard coding to address a potential security risk in DeauxSphere… promptware grateful for my detailed requirements description 🤓🙌🏾 .
August 25, 2026 at 5:09 PM
#promptware ?

For realises?

Sounds like someone read to many #potatopunk stories...

...sounds bad if tru...tell me it ain't so !

#infosec #aisecurity
August 25, 2026 at 11:24 AM
#promptware ?

For realises?

Sounds like someone read to many #cyberpunk stories...

...sounds bad if tru...tell me it ain't so !

#infosec #aisecurity
August 25, 2026 at 11:21 AM
The Biggest New Threat to Smart Homes Is AI Promptware. My Tips Help Stop It
www.cnet.com/home/securit...
The Biggest New Threat to Smart Homes Is AI Promptware. My Tips Help Stop It - CNET
Prompt injections into AI have created a new world of home-hacking opportunities. Here's how it works and my steps to protect yourself.
www.cnet.com
July 31, 2026 at 2:00 PM
Prompt injection is not the new SQL injection. Schneier and co have reframed prompt injection as 'promptware': a full 7-stage kill chain. The uncomfortable truth: LLMs can't distinguish instructions from data. This isn't a bug you can patch. Read the filing #AI #infosec #cybersecurity
Prompt injection is not the new SQL injection | Steelwise
Schneier et al have reframed prompt injection as
steelwise.uk
July 20, 2026 at 10:30 AM
The Biggest New Threat to Smart Homes Is AI Promptware. My Tips Help Stop It
The Biggest New Threat to Smart Homes Is AI Promptware. My Tips Help Stop It
Prompt injections into AI have created a new world of home-hacking opportunities. Here's how it works and my steps to protect yourself.
www.cnet.com
July 14, 2026 at 6:03 PM
Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting

Aya Spira et al.

#arXiv #cs.CR
Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
The growing adoption of agentic LLM applications has introduced a new threat previously named as promptware. While prior work has established that adversaries can exploit direct channels to LLM applications to apply promptware under weak threat models, many applications do not provide any direct ch…
arxiv.org
July 9, 2026 at 10:23 PM
Beware Of Agentic Botnets: Scalable Untargeted Promptware Attacks Via Universal And Transferable Adversarial HalluSquatting https://packetstorm.news/files/225522 #paper
July 9, 2026 at 6:45 PM
you don't breach anything. you register the fake package names the model reliably hallucinates, then wait for it to install your botnet for you https://sites.google.com/view/agentic-botnets/home
Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSquatting
Involved Researchers: Aya Spira, Tel Aviv University Stav Cohen, Technion Elad Feldman, Tel Aviv University Ron Bitton, Intuit Avishai Wool, Tel Aviv University Ben Nassi, Tel Aviv University
sites.google.com
July 9, 2026 at 2:27 PM
Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, Ben Nassi: Beware of Agentic Botnets: Scalable Untargeted Promptware Attacks via Universal and Transferable Adversarial HalluSqu... https://arxiv.org/abs/2607.07433 https://arxiv.org/pdf/2607.07433 https://arxiv.org/html/2607.07433
July 9, 2026 at 6:39 AM
Link to the research site below.

Poor style choice to put the link under a short link text without giving it at the end of the article, a good convention to follow imo.

sites.google.com/view/agentic...
July 8, 2026 at 1:49 PM
Nový typ škodlivého softvéru nazvaný promptware využíva generatívne AI chatboty a agentov. Útočníci využívajú techniky ako "prompt injection" a "jailbreaking", aby získali prístup k systémom, získať informácie a diaľkovo ich ovládať.
Nový druh malvéru: Promptware a využitie umelej inteligencie
Nový typ škodlivého softvéru nazvaný promptware využíva generatívne AI chatboty a agentov. Útočníci využívajú techniky ako "prompt injection" a "jailbreaking", aby získali prístup k systémom, získať informácie a diaľkovo ich ovládať.
altky.sk
June 28, 2026 at 10:26 PM
Nový typ škodlivého softvéru nazvaný promptware využíva generatívne AI chatboty a agentov. Útočníci využívajú techniky ako "prompt injection" a "jailbreaking", aby získali prístup k systémom, získať informácie a diaľkovo ich ovládať.
Nový druh malvéru: Promptware a využitie umelej inteligencie
Už ste pravdepodobne počuli o malvéri, ransoméri a špionáži. Teraz je tu nový hráč na scéne – promptware. Táto novinka predstavuje úplne nový model škodlivého softvéru, ktorý využíva generatívne AI chatboty alebo agentov. Ako uvádzajú Bruce Schneier a jeho spolupracovníci, reťazec zabíjania (kill chain) promptwaru je podrobný postup, ktorý opisuje fázy kybernetického útoku od prvotného prístupu až po dosiahnutie cieľov útočníka. Poďme sa na tento reťazec pozrieť a zistiť, ako môžeme lepšie pochopiť hrozbu a možno aj zabrániť jej. ### This post is for subscribers only Become a member to get access to all content Subscribe now
altky.sk
June 28, 2026 at 10:21 PM
Prompt injection is not the new SQL injection. Schneier and co have reframed prompt injection as 'promptware': a full 7-stage kill chain. The uncomfortable truth: LLMs can't distinguish instructions from data. This isn't a… https://steelwise.uk/filings/prompt-injection-is-not-the-new-sql-injection/
Prompt injection is not the new SQL injection | Steelwise
Schneier et al have reframed prompt injection as
steelwise.uk
May 25, 2026 at 2:00 PM
Feed: "Plugged In"
By: Bret Eckelberry on Thursday, April 16, 2026
Thanks, AI: The New Danger of Promptware
The widespread adoption of AI has brought with it some new security vulnerabilities. One such issue? The rise of "promptware."
www.pluggedin.com
April 17, 2026 at 2:03 PM
Thirty one companies are already hiding commands in Summarise with AI buttons to steer assistant output. Schneier’s team maps this as step one in a seven step promptware kill chain that can end in data theft, financial fraud, or real world impact. Stay tuned 👉 blog.mailfence.com/newsletter-sign
Privacy is a Right, not a Feature - Mailfence Blog
Private email by Mailfence - Everything you need to know about email privacy, security, encryption and email etiquette.
blog.mailfence.com
April 15, 2026 at 6:03 AM
>総務省、AI開発者・AI提供者向けに「AIのセキュリティ確保のための技術的対策に係るガイドライン」を公表 - INTERNET Watch
https://internet.watch.impress.co.jp/docs/news/2097778.html

先日書いた拙文「プロンプトウェア・キルチェーン」も併せてどうぞ(宣伝w)
https://text.baldanders.info/remark/2026/02/the-promptware-kill-chain/
総務省、AI開発者・AI提供者向けに「AIのセキュリティ確保のための技術的対策に係るガイドライン」を公表
総務省は3月27日、AI開発者・提供者向けに「AIのセキュリティ確保のための技術的対策に係るガイドライン」を公表した。
internet.watch.impress.co.jp
April 1, 2026 at 11:18 PM
Attacken auf große Sprachmodelle gehen mittlerweile weit über reine Prompt-Injections hinaus. Zeit für eine Bestandsaufnahme. #Malware
heise+ | Promptware: Wie weit Malware für KI-Systeme schon ist
Attacken auf große Sprachmodelle gehen mittlerweile weit über reine Prompt-Injections hinaus. Zeit für eine Bestandsaufnahme.
www.heise.de
April 1, 2026 at 7:03 AM
Nové hrozby v kybernetickej bezpečnosti: hacknutie Xbox One po 10 rokoch, útoky „promptware“ na AI, zmena paradigmy cloudovej bezpečnosti a využívanie zabudovaných nástrojov ransomwaru. Dôležité je zabezpečiť celé ekosystémy a staré systémy kritickej infraštruktúry.
Nové hrozby a prekvapivé zistenia: kybernetická bezpečnosť v roku 2026
Nové hrozby v kybernetickej bezpečnosti: hacknutie Xbox One po 10 rokoch, útoky „promptware“ na AI, zmena paradigmy cloudovej bezpečnosti a využívanie zabudovaných nástrojov ransomwaru. Dôležité je zabezpečiť celé ekosystémy a staré systémy kritickej infraštruktúry.
altky.sk
March 25, 2026 at 11:03 PM