Prompts Are The New Malware: Enterprise AI Defenses Lag Behind Evolving Threats
The cybersecurity landscape is undergoing a profound transformation, with prompt injection emerging as a potent new vector for malicious activity. A recent CrowdStrike report, detailed in Forbes, reveals that these sophisticated attacks have impacted more than 90 organizations in 2025 alone, effectively weaponizing prompts to facilitate the theft of credentials and cryptocurrencies.
The report underscores a dramatic increase in AI-enabled adversary operations, which surged by 89% year-over-year. A striking 82% of these intrusions were executed without the use of traditional malicious code, indicating a fundamental shift in attack methodologies. This evolution is particularly concerning as enterprises increasingly integrate AI agents with broad access privileges into their operations, inadvertently expanding their attack surface.
Prompt injection has consequently risen to become the leading vulnerability on the OWASP Top 10 for Large Language Models (LLMs). This vulnerability arises from the inherent difficulty AI models face in distinguishing between legitimate developer instructions and malicious commands embedded within user inputs or retrieved data. Attacks can be direct, where users deliberately override prompts, or indirect, involving the embedding of malicious instructions in seemingly innocuous content like emails or web pages.
Notable incidents include data exfiltration from Slack AI and the 'EchoLeak' zero-click prompt injection against Microsoft 365 Copilot, which demonstrated the ability to forward internal files via a specially crafted email without user interaction. While these specific vulnerabilities were patched, the underlying class of attack persists and continues to expand across agentic stacks and Retrieval Augmented Generation (RAG) pipelines.
The analyst community is responding to these evolving threats. Gartner, for instance, advised CISOs in December 2025 to block all AI browsers, citing concerns over indirect prompt injection, credential exposure, and the absence of mature controls. The rapid pace of AI adoption and the expanding vulnerability surface necessitate a re-evaluation of enterprise AI defenses, as traditional security measures are proving inadequate against these advanced, AI-driven threats.
Read original source