Threat · curated 27 Sep 2026

Indirect Prompt Injection Targeting AI Ad Review Systems

Coverage timeline

27 Sep 2026gurucul.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Indirect prompt injection against automated AI ad reviewers shows attackers weaponizing hidden web content to override AI decision-making, creating brand and compliance risk that traditional static content filters cannot detect.

An active indirect prompt injection campaign targets AI-based advertisement review systems by hiding malicious instructions inside advertiser landing pages using CSS to make text invisible to human reviewers while remaining readable to AI text processors. At least 10 domains registered between April 21-24, 2026 were identified, with three payload variants that impersonate internal compliance directives to trick AI reviewers into approving policy-violating ads.