#promptware
Attacks on LLM-based systems have evolved into a distinct class of malware execution mechanisms. Bruce Schneier, Oleg Brodt, Elad Feldman, and Ben Nassi propose a “promptware kill chain” to provide policymakers with a framework to address the escalating AI threat landscape.
The Promptware Kill Chain
Prompt injection attacks against AI models are not simple attacks; they are the first step of a kill chain. Understanding this gives defenders a set of countermeasures.
www.lawfaremedia.org
February 13, 2026 at 4:17 PM
“Prompt injection” is the wrong mental model.

LLM attacks increasingly look like malware campaigns, not single exploits. This paper frames them as promptware and maps a 5-stage kill chain: initial access → priv esc → persistence → lateral movement → actions on objective.
arxiv.org/html/2601.09...
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multi-Step Malware
arxiv.org
January 15, 2026 at 5:03 PM
Promptware. A lecture on security and the evolution of security issues by implementing generative AI into software.
From Prompt Injection to Promptware: Evolution of Attacks Against LLM Applications | Ben Nassi
YouTube video by Zenity
www.youtube.com
December 9, 2025 at 1:54 PM
Fragments: LLMs make our days harder, an LLM reacts badly to a rejected pull request, the Promptware Kill Chain, horror and elation trying Claude Code for two weeks, Free Speech Poseurs' silence to real threats

martinfowler.com/fragments/20...
Fragments: February 19
fragments 19 Feb 2026
martinfowler.com
February 19, 2026 at 2:44 PM
Attacken auf große Sprachmodelle gehen mittlerweile weit über reine Prompt-Injections hinaus. Zeit für eine Bestandsaufnahme. #Malware
heise+ | Promptware: Wie weit Malware für KI-Systeme schon ist
Attacken auf große Sprachmodelle gehen mittlerweile weit über reine Prompt-Injections hinaus. Zeit für eine Bestandsaufnahme.
www.heise.de
April 1, 2026 at 7:03 AM
A new attack called #Promptware uses a Google Calendar invite to hijack a user's Gemini AI, allowing access to personal data and even smart home controls.

Read: hackread.com/promptware-a...

#AIsecurity #Cybersecurity #Goolge #GeminiAI
New Promptware Attack Hijacks User's Gemini AI Via Google Calendar Invite
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
August 7, 2025 at 11:08 AM
#promptware ?

For realises?

Sounds like someone read too many #potatopunk stories...

...sounds bad if tru...tell me it ain't so !

#infosec #aisecurity
August 25, 2026 at 8:04 PM
Researchers (including Bruce Schneier) analyzed 36 real-world incidents and found that prompt injections have quietly evolved into a full malware delivery system.

They're dubbing it "promptware."

Read: arxiv.org/abs/2601.09625
The Promptware Kill Chain: How Prompt Injections Gradually Evolved Into a Multistep Malware Delivery Mechanism
Prompt injection was initially framed as the large language model (LLM) analogue of SQL injection. However, over the past three years, attacks labeled as prompt injection have evolved from isolated…
arxiv.org
February 11, 2026 at 6:50 PM
promptware is the new nightmare: #hackers turning ai prompts into full #malware that spreads via emails, git repos, and llm memory.
researchers including bruce schneier detailed 36 real incidents where #prompt injections evolved into persistent malware delivery.
February 12, 2026 at 3:20 AM
-SVR takes over Wagner's info-ops
-APT28 still on the Word macros
-BeyondTrust RCE exploitation goes wild
-20-year-old bug in Munge supercomputer software
-Dava pharmacy chain exposed an API will all its data
-New "promptware" concept
-Proofpoint acquires Acuvity
February 16, 2026 at 10:29 AM
Beware of promptware: How researchers broke into Google Home via Gemini

This was just a demonstration, but you can take steps to protect yourself from similar promptware attacks.

#gemini #hackernews #news
Beware of promptware: How researchers broke into Google Home via Gemini
This was just a demonstration, but you can take steps to protect yourself from similar promptware attacks.
www.zdnet.com
August 8, 2025 at 11:41 PM
At the #BlackHat #cybersecurity conference in Las Vegas, a team of researchers revealed how Gemini can be weaponized via Targeted Promptware Attacks. 👉

Read more on PCMag:

bit.ly/3Hrut8U
August 10, 2025 at 1:27 PM
Indirect Prompt Injection Attacks Against LLM Assistants

Really good research on practical attacks against LLM agents. "Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous" Abstract: The growing integration of LLMs into…
Indirect Prompt Injection Attacks Against LLM Assistants
Really good research on practical attacks against LLM agents. "Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous" Abstract: The growing integration of LLMs into applications has introduced new security risks, notably known as Promptware­ -- maliciously engineered prompts designed to manipulate LLMs to compromise the CIA triad of these applications. While prior research warned about a potential shift in the threat landscape for LLM-powered applications, the risk posed by Promptware is frequently perceived as low.
www.schneier.com
September 3, 2025 at 11:01 AM
Indirect Prompt Injection Attacks Against LLM Assistants

LLMs' integration in applications introduces new security vulnerabilities, specifically Promptware. Promptware utilizes malicious prompts to compromise the CIA triad of these applications. This research assesses Pro…

#gemini #hackernews #llm
Indirect Prompt Injection Attacks Against LLM Assistants
LLMs' integration in applications introduces new security vulnerabilities, specifically Promptware. Promptware utilizes malicious prompts to compromise the CIA triad of these applications. This research assesses Promptware risks for users of Gemini-powered assistants through a new TARA framework. The study focuses on Targeted Promptware Attacks, utilizing indirect prompt injection through common user interactions. Fourteen attack scenarios against Gemini assistants across five threat classes were demonstrated. These attacks have digital and physical consequences, like spamming, phishing, and home automation control. The research reveals Promptware's potential for device lateral movement beyond the LLM application's boundaries. The TARA analysis reveals 73% of the threats pose a high-critical risk to users. Mitigations were discussed to reduce the risk significantly. The findings were disclosed to Google, who deployed dedicated mitigations. The research highlights the real-world dangers of Promptware and the importance of security measures.
securityboulevard.com
September 4, 2025 at 7:00 AM
So, is this prompt injection issue from this summer not related and/or fixed? arstechnica.com/google/2025/...
October 15, 2025 at 12:45 PM
Hard coding to address a potential security risk in DeauxSphere… promptware grateful for my detailed requirements description 🤓🙌🏾 .
August 25, 2026 at 5:09 PM
Researchers have dubbed a new class of attacks “promptware” and outlined a seven-stage kill chain. The AI industry risks underestimating threats if it treats prompt injection as a single vulnerability. Multi-stage defenses are needed. https://bit.ly/46fKNmt
February 23, 2026 at 2:04 PM
Темы за последние 30 минут 🧭:

1. Модели 🆕
2. Сами 🆕
3. Мало 🆕
4. Хадсона 🆕
5. Цепь 🆕
6. Убийства 🆕
7. Promptware 🆕
8. Атаки 🆕
9. Современные 🆕
10. Генеративные 🆕

Реклама: @terraprotege.bsky.social.
February 17, 2026 at 12:01 AM
#promptware ?

For realises?

Sounds like someone read to many #cyberpunk stories...

...sounds bad if tru...tell me it ain't so !

#infosec #aisecurity
August 25, 2026 at 11:21 AM
www.schneier.com/blog/archive...

"We need some new fundamental science of LLMs before we can solve this"
Indirect Prompt Injection Attacks Against LLM Assistants - Schneier on Security
Really good research on practical attacks against LLM agents. “Invitation Is All You Need! Promptware Attacks Against LLM-Powered Assistants in Production Are Practical and Dangerous” Abstract: The growing integration of LLMs into applications has introduced new security risks, notably known as Promptware­—maliciously engineered prompts designed to manipulate LLMs to compromise the CIA triad of these applications. While prior research warned about a potential shift in the threat landscape for LLM-powered applications, the risk posed by Promptware is frequently perceived as low. In this paper, we investigate the risk Promptware poses to users of Gemini-powered assistants (web application, mobile application, and Google Assistant). We propose a novel Threat Analysis and Risk Assessment (TARA) framework to assess Promptware risks for end users. Our analysis focuses on a new variant of Promptware called Targeted Promptware Attacks, which leverage indirect prompt injection via common user interactions such as emails, calendar invitations, and shared documents. We demonstrate 14 attack scenarios applied against Gemini-powered assistants across five identified threat classes: Short-term Context Poisoning, Permanent Memory Poisoning, Tool Misuse, Automatic Agent Invocation, and Automatic App Invocation. These attacks highlight both digital and physical consequences, including spamming, phishing, disinformation campaigns, data exfiltration, unapproved user video streaming, and control of home automation devices. We reveal Promptware’s potential for on-device lateral movement, escaping the boundaries of the LLM-powered application, to trigger malicious actions using a device’s applications. Our TARA reveals that 73% of the analyzed threats pose High-Critical risk to end users. We discuss mitigations and reassess the risk (in response to deployed mitigations) and show that the risk could be reduced significantly to Very Low-Medium. We disclosed our findings to Google, which deployed dedicated mitigations...
www.schneier.com
September 3, 2025 at 2:14 PM
Prompt injection, or feeding rogue instructions to an artificial intelligence system, merits its own classification as "promptware" - malware that uses a large language model as its own execution engine, say researchers.
www.databreachtoday.com/promptware-a...
'Promptware' Attacks Await an Unprepared AI Industry
The large language model industry has mostly treated prompt injection attacks as a risk analogous to traditional web server prompt injection attacks. Researchers
www.databreachtoday.com
February 21, 2026 at 11:19 AM
1990: freeware
1995: warez
1999: shareware
2004: adware
2007: appware
2011: cloudware
2016: bloatware
2020: remoteware
2023: promptware
2024: modelware
2025: vibeware
2026: agentware
March 12, 2026 at 4:01 PM