Tuesday, September 15, 2026

CrowdStrike Uncovers 5 New Prompt Injection Techniques Targeting AI Agents

CrowdStrike has identified five new techniques for prompt injection targeting AI agents, emphasizing the rapid evolution of adversarial methods as enterprises increasingly deploy autonomous AI systems.

Detailed in a report published on July 7, 2026, by CrowdStrike’s AI security research team, these techniques expand the company’s prompt injection taxonomy to over 200 documented attack methods.

This reinforces concerns that AI agents, capable of accessing files, executing commands, and interacting with external systems, are becoming high-value targets for attacks.

5 New Prompt Injection Techniques

Prompt injection has emerged as a critical security challenge in the AI era, particularly as the landscape shifts from standalone chatbots to fully operational AI agents integrated into enterprise workflows.

Unlike traditional direct attacks, modern prompt injection campaigns often rely on indirect vectors, embedding malicious instructions within data sources such as web pages, emails, APIs, or SaaS content consumed by AI systems.

These hidden payloads can manipulate agent behavior, bypass safeguards, and trigger unauthorized actions without the user’s explicit awareness.

Among the newly disclosed techniques, Trigger-Activated Rule Addition (PT0201) introduces delayed-execution logic in which malicious instructions remain dormant until a specific condition or keyword activates them. This “sleeping payload” approach makes detection difficult during initial inspections while enabling attackers to alter agent behavior later.

Another technique, Cognitive Token Suppression (PT0197), targets the model’s linguistic safeguards by limiting its use of refusal-related or policy-driven language, increasing the likelihood of unsafe or ambiguous responses.

Algorithmic Payload Decomposition (PT0200) represents a sophisticated evasion method in which malicious instructions are fragmented into seemingly benign components. When processed collectively, the AI reconstructs these elements into an actionable command, effectively bypassing traditional filtering mechanisms.

Similarly, Special Token Injection (PT0198) exploits structural delimiters and formatting cues used by AI systems, allowing attackers to disguise user input as system-level instructions or tool commands, thereby elevating privilege and execution priority.

The fifth technique, Unwitting User Delivery (IM0005), leverages social engineering to convert legitimate users into attack vectors. By tricking users into submitting malicious prompts, often via copied text, embedded media, or compromised browser extensions, attackers can execute payloads within authenticated sessions, significantly increasing their impact while reducing the likelihood of detection.

Key Techniques Identified:

  • Trigger-Activated Rule Addition (PT0201): Dormant instructions activated by specific keywords or events.
  • Cognitive Token Suppression (PT0197):Restricts safety-related vocabulary to weaken refusal mechanisms.
  • Algorithmic Payload Decomposition (PT0200): Splits malicious commands into benign fragments for later reconstruction.
  • Special Token Injection (PT0198): Mimics system-level formatting to escalate instruction priority.
  • Unwitting User Delivery (IM0005):Uses social engineering to deliver malicious prompts through trusted users.

For security teams, these developments signify a shift toward multi-stage, composite prompt injection attacks that combine obfuscation, delayed triggers, and contextual manipulation.

Effective defense now requires comprehensive AI threat modeling across all input channels, advanced red teaming that simulates indirect and hybrid attack scenarios, and runtime visibility into AI interactions.

CrowdStrike emphasizes that detection strategies must evolve beyond simple pattern recognition to account for chained techniques and contextual abuse.

These findings underscore the growing need for unified AI security platforms capable of monitoring prompt flows, enforcing policy controls, and detecting anomalous behavior across AI agents, tools, and data pipelines in real time.

Interact with Cyber Threats in Windows, Linux, macOS VMs to Trigger Full Attack Chain - Analyse Malware & Phishing with ANY RUN

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a...

Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users

A Casbaneiro banking Trojan campaign targeting users across Latin...

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

Related Articles

Recent News