Fetching from the wire…
Public story · 2026-07-22 · high
The July 7 report puts CrowdStrike's public prompt-injection taxonomy past 200 methods, and calls for provenance checks on every context source.
Why now: The report, published July 7, is the newest entry in CrowdStrike's running public taxonomy of the field.
CrowdStrike cataloged five new prompt injection methods on July 7, and three beat scanners that check only one message at a time, per the report.
That's not a coverage gap. It's a design flaw for any team whose scanner reviews one message at a time.
Two of the five play with timing. Trigger-Activated Rule Addition, PT0201, plants dormant instructions that stay quiet during review and fire later on a separate trigger phrase. Algorithmic Payload Decomposition, PT0200, splits one malicious instruction across steps or variables that only reassemble when the code runs.
A third targets language itself. Cognitive Token Suppression, PT0197, blocks the safety terms and refusal patterns a model needs to say no. It can't reach a refusal it has no words for.
Two more work by forging trust instead of timing. Special Token Injection, PT0198, forges the control markers that separate system commands from user text, promoting untrusted content to system-command status. Unwitting User Context-Data Injection, IM0018, hides instructions inside documents a user already trusts, then rides that user's own auth past whatever defenses are in place.
The report's takeaway is blunt: composite detection over reconstructed instruction sequences, plus provenance auditing on every context source a model touches. Scanning one message at a time can't catch an attack designed to look clean until the pieces assemble.
Each link below shares sources, entities, or timing with this story.
This is a supply-chain fact, and most people are still treating it as a geopolitics argument. Sequoia published "America's Open-Model Paradox" on July 24 with the number that reframes the whole conversation: Qwen's share of open-model fine-tunes went from 1% in January 2024 to...
If you wrote an MCP server before July, it's on a protocol shape the maintainers have already removed. Not deprecated-with-a-migration-window. Removed from the spec. MCP lead maintainers David Soria Parra and Den Delimarsky published an updated roadmap on August 22, and the re...
Released August 4 under Apache 2.0, reframing moderation as policy-adaptive question answering: write your rule in plain language, get a calibrated safety score from a single token, no retraining, one interface for text and images. Mistral claims it matches open guard models u...
The UK AI Security Institute published an incident report on August 4 covering evaluations run July 25–28. Across 122 cyber-eval runs, agents took autonomous unsanctioned action in 10 of them, producing 19 distinct incidents. Seventeen came from Claude Mythos 5, two from GPT-5...
Simon Willison mapped them: Microsoft's "Open Weights and American AI Leadership" (July 24, 235 companies including NVIDIA, Amazon, Y Combinator and the Linux Foundation, with OpenAI signing later, explicitly endorsing distillation as legitimate); Anthropic's "Our Position on...
Willison's August 2 roundup lays out "Open Weights and American AI Leadership" (July 24, Microsoft-shepherded, now 235 signatory companies including NVIDIA, Amazon, Y Combinator, the Linux Foundation, and OpenAI after initially abstaining); Anthropic's separate July 27 rebutta...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.