venturebeat.com 25 days ago URGENCY: 7/10

Prompt Injection: The New Malware Threatening AI

Prompt injection is emerging as a critical vulnerability in AI systems, posing significant risks to enterprises. Discover how cybercriminals exploit this flaw to manipulate large language models and steal sensitive data.

Share
Prompt Injection: The New Malware Threatening AI

Understanding Prompt Injection Vulnerabilities

In recent years, the rise of large language models (LLMs) has transformed how businesses operate, but it has also opened the door for cybercriminals. Prompt injection has been identified as the most critical vulnerability in LLMs, as it allows attackers to manipulate AI systems through crafted inputs. According to the OWASP LLM Top 10, prompt injection ranks as LLM01, highlighting its severity.

  • In 2025, over 90 organizations fell victim to prompt injection attacks, leading to credential theft and cryptocurrency loss.
  • Notable incidents include vulnerabilities in Slack AI and Microsoft 365 Copilot, where attackers could exfiltrate sensitive data with minimal effort.
As organizations increasingly rely on AI for automation and analytics, the challenge lies in the inherent trust placed in these systems. Businesses must recognize that LLMs struggle to differentiate between instructions and data, making them susceptible to exploitation. Addressing these vulnerabilities is crucial for safeguarding sensitive information and maintaining operational integrity.