Skip to content

CrowdStrike Documents Five New Prompt-Injection Techniques Against AI Systems

The bottom line: CrowdStrike documents five new prompt-injection techniques that can manipulate LLMs into executing unauthorized commands.

Security firm CrowdStrike has identified five new prompt-injection techniques that threaten enterprise AI systems. These attack vectors exploit LLMs by causing them to accept instructions that humans would have recognized as suspicious.

CrowdStrike has expanded its classification of prompt-injection attacks to include five new techniques. The first is Trigger-Activated Rule Addition: An attacker adds a new rule that initially appears harmless but can be activated later to trigger undesired model behavior.

Cognitive Token Suppression circumvents built-in security measures by diverting the model’s linguistic patterns away from established refusal patterns. Algorithmic Payload Decomposition distributes commands across multiple stages that individually appear harmless but can be combined to form a dangerous instruction.

Special Token Injection functions similarly to embedding fake control switches in normal instructions — the attacker creates confusion and causes the model to treat untrusted user content as high-level system directives. Unwitting User Context-Data Injection exploits the boundary between trusted data and executable commands: a user is tricked into injecting malicious instructions as part of the context data for an LLM — for example, during document upload or when adding content that will later be processed by AI systems.

CrowdStrike recommends security teams implement threat modeling for every possible origin of model context, extended test coverage, and detection capabilities that also cover composite attacks.


Source: www.csoonline.com · Published July 10, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: