Research · curated 18 Jul 2026

CrowdStrike Uncovers New Prompt Injection Techniques

Coverage timeline

8 Jul 2026cybersecuritynews.com 19 Jul 2026crowdstrike.comprimary

Why it matters

CrowdStrike's expanded prompt injection taxonomy gives defenders concrete, named techniques—like sleeping trigger rules and fragmented payloads that evade scanners—to test and harden agentic AI systems against indirect injection.

CrowdStrike's AI security research team disclosed 18 new additions to its prompt injection taxonomy, expanding coverage to over 200 techniques, and detailed five notably: Trigger-Activated Rule Addition (PT0201), Cognitive Token Suppression (PT0197), Algorithmic Payload Decomposition (PT0200), Special Token Injection (PT0198), and one further method. The techniques target AI agents that crawl webpages, access file stores, and run shell commands, using indirect injection to hide malicious instructions in consumed data.