Skip to content
Vulnerabilities

CrowdStrike Unveils 5 New Prompt Injection Techniques Challenging AI Agents

CrowdStrike has introduced five new prompt injection techniques, highlighting the growing threat to AI agents as organizations increasingly deploy autonomous AI systems. While early risks focused on simple chatbot manipulation, the rise of AI agents capable of browsing websites, accessing internal d...

· Jul 09, 2026 · 3 min read · 👁 4 views
CrowdStrike Unveils 5 New Prompt Injection Techniques Challenging AI Agents

CrowdStrike has introduced five new prompt injection techniques, highlighting the growing threat to AI agents as organizations increasingly deploy autonomous AI systems.

While early risks focused on simple chatbot manipulation, the rise of AI agents capable of browsing websites, accessing internal data, and executing commands has significantly expanded the attack surface.

Adversaries are now embedding malicious instructions within the data these agents consume, enabling indirect attacks that can hijack system behavior without obvious signs.

To address this growing challenge, CrowdStrike has expanded its prompt injection taxonomy with 18 new techniques, bringing the total to more than 200 documented methods.

Among these, five newly highlighted techniques demonstrate how attackers are refining their strategies to evade detection and subtly manipulate AI systems.

5 New Prompt Injection Techniques

One of the most notable techniques is Trigger-Activated Rule Addition, where attackers plant hidden instructions that remain dormant until a specific condition or keyword activates them.

These “sleeping” payloads can bypass initial security reviews and later alter system behavior, such as silently exfiltrating sensitive data once triggered.

Another emerging method, Cognitive Token Suppression, attempts to limit an AI model’s ability to generate safe responses by restricting the use of refusal or policy-related language.

By steering the model away from its normal safety vocabulary, attackers increase the likelihood of ambiguous or non-compliant outputs.

Algorithmic Payload Decomposition represents a more technical evasion tactic. Instead of delivering a malicious instruction directly, attackers break it into smaller, seemingly harmless components.

  • Trigger-Activated Rule Addition (PT0201): Hidden triggers activate malicious instructions only when specific conditions are met.
  • Cognitive Token Suppression (PT0197): Manipulates prompts to make the AI ignore or overlook important instructions.
  • Algorithmic Payload Decomposition (PT0200): Splits a malicious prompt into smaller parts to evade detection.
  • Special Token Injection (PT0198): Uses special or control tokens to alter the AI’s behavior or bypass safeguards.
  • Unwitting User Delivery (IM0005): Tricks users into unknowingly delivering malicious prompts to an AI system.

The AI is then guided to reconstruct these fragments into a complete command, allowing the payload to bypass traditional filters that scan for obvious threats.

Special Token Injection targets the structural framework of AI systems. By mimicking internal formatting elements such as tool calls or system-level instructions, attackers attempt to blur the boundary between trusted and untrusted inputs.

This can trick the model into treating malicious content as a legitimate command with elevated priority. The fifth technique, Unwitting User Delivery, leverages social engineering rather than technical manipulation alone.

In this scenario, attackers persuade users to input malicious prompts themselves, often through deceptive content such as viral posts or hidden instructions embedded in media, the CrowdStrike advisory reads.

Because the request originates from a legitimate user session, it becomes harder for security systems to detect. These developments signal a shift in how prompt injection attacks operate. Rather than relying on obvious jailbreak attempts, attackers are increasingly using layered techniques involving hidden context, delayed execution, and formatting tricks.

This makes detection more complex and requires security teams to rethink their approach. CrowdStrike emphasizes that organizations must expand AI threat modeling to include all possible data sources, from prompts and APIs to emails and SaaS platforms.

Detection strategies also need to account for multi-stage attacks, where several techniques are combined into a single exploit chain.

As AI adoption accelerates, these newly identified techniques underline a clear reality: securing AI agents requires continuous adaptation, deeper visibility, and a more comprehensive understanding of how attackers manipulate both language and context.

Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor ChecklistDownload Free AI SOC SLA Guide

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you