Google researchers report a sharp increase in prompt injection attempts against LLM-integrated products, though most attempts remain low-sophistication.
Treat model output as untrusted input, isolate tool-call permissions, and log every model-to-tool boundary — the standard controls still work when they are actually applied.
