Research · curated 18 Jul 2026
CrowdStrike Uncovers New Prompt Injection Techniques
First reported · updated · 2 reports crowdstrike.com
Coverage timeline
Why it matters
CrowdStrike's expanded prompt injection taxonomy gives defenders concrete, named techniques—like sleeping trigger rules and fragmented payloads that evade scanners—to test and harden agentic AI systems against indirect injection.
CrowdStrike's AI security research team disclosed 18 new additions to its prompt injection taxonomy, expanding coverage to over 200 techniques, and detailed five notably: Trigger-Activated Rule Addition (PT0201), Cognitive Token Suppression (PT0197), Algorithmic Payload Decomposition (PT0200), Special Token Injection (PT0198), and one further method. The techniques target AI agents that crawl webpages, access file stores, and run shell commands, using indirect injection to hide malicious instructions in consumed data.