CrowdStrike's five new prompt injection techniques include dormant trigger rules and payloads fragmented across benign steps
A July 7 CrowdStrike report adds five techniques to a taxonomy now exceeding 200 documented attack methods: Trigger-Activated Rule Addition (PT0201) plants dormant instructions that fire only on a later trigger phrase, passing initial review; Cognitive Token Suppression (PT0197) blocks safety terms and refusal patterns so the model can't linguistically reach a refusal; Algorithmic Payload Decomposition (PT0200) splits a malicious instruction across steps or variables that only reassemble at execution; Special Token Injection (PT0198) forges control markers and delimiters to promote untrusted content to system-command status; and Unwitting User Context-Data Injection (IM0018) hides instructions in trusted documents and emails, riding the user's own authentication past defenses. The builder takeaway is that per-message scanning is now structurally insufficient — three of the five are invisible to any check that looks at one input in isolation, so you need composite detection over reconstructed instruction sequences plus provenance auditing on every context source.
Source
↳ Follow the thread