Fetching from the wire…
Public story · 2026-07-22 · high
The July 7 report puts CrowdStrike's public prompt-injection taxonomy past 200 methods, and calls for provenance checks on every context source.
Why now: The report, published July 7, is the newest entry in CrowdStrike's running public taxonomy of the field.
CrowdStrike cataloged five new prompt injection methods on July 7, and three beat scanners that check only one message at a time, per the report.
That's not a coverage gap. It's a design flaw for any team whose scanner reviews one message at a time.
Two of the five play with timing. Trigger-Activated Rule Addition, PT0201, plants dormant instructions that stay quiet during review and fire later on a separate trigger phrase. Algorithmic Payload Decomposition, PT0200, splits one malicious instruction across steps or variables that only reassemble when the code runs.
A third targets language itself. Cognitive Token Suppression, PT0197, blocks the safety terms and refusal patterns a model needs to say no. It can't reach a refusal it has no words for.
Two more work by forging trust instead of timing. Special Token Injection, PT0198, forges the control markers that separate system commands from user text, promoting untrusted content to system-command status. Unwitting User Context-Data Injection, IM0018, hides instructions inside documents a user already trusts, then rides that user's own auth past whatever defenses are in place.
The report's takeaway is blunt: composite detection over reconstructed instruction sequences, plus provenance auditing on every context source a model touches. Scanning one message at a time can't catch an attack designed to look clean until the pieces assemble.
Each link below shares sources, entities, or timing with this story.
CrowdStrike partners with Accenture / Shared entity: July / Earlier coverage
Linked by a graph relationship (CrowdStrike partners with Accenture); both cover July; earlier July coverage from 2026-07-16.
OpenAI partners with CrowdStrike / Shared entity: July / Earlier coverage
Linked by a graph relationship (OpenAI partners with CrowdStrike); both cover July; earlier July coverage from 2026-07-11.
OpenAI partners with CrowdStrike / Shared entity: July / Earlier coverage / Tension
Linked by a graph relationship (OpenAI partners with CrowdStrike); both cover July; earlier July coverage from 2026-07-10.
Linked by a graph relationship (OpenAI partners with CrowdStrike); both cover July; earlier July coverage from 2026-06-28.
OpenAI partners with CrowdStrike / Shared entity: July / Earlier coverage
Linked by a graph relationship (OpenAI partners with CrowdStrike); both cover July; earlier July coverage from 2026-07-21.
Linked by a graph relationship (OpenAI partners with CrowdStrike); both cover July; earlier July coverage from 2026-07-20.
Linked by a graph relationship (OpenAI partners with CrowdStrike); both cover July; earlier July coverage from 2026-07-20.
Linked by a graph relationship (OpenAI partners with CrowdStrike); both cover July; earlier July coverage from 2026-07-16.