Analysis · curated 21 Sep 2026

Prompt Injection Attacks Exposed: AI as a Coworker in 2026

Coverage timeline

26 Aug 2026ondefend.com

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Multi-turn jailbreaks like Crescendo evade single-shot filters by talking models into a compliant state, meaning defenders can no longer rely on pattern-matching individual malicious prompts to protect AI systems with access to sensitive corporate data.

OnDefend red-team lead Erik Dominguez discusses in an interview how AI attacks have shifted from single-shot prompt-injection payloads to multi-turn persuasion campaigns, citing the published Crescendo technique that gradually escalates dialogue to jailbreak models like ChatGPT, Gemini, and LLaMA. The piece frames prompt injection's rise to the top of OWASP's AI risk list and how jailbreaking and prompt injection are converging as users treat AI as a trusted coworker with access to inboxes, codebases, and ticket queues.