CrowdStrike flags new AI prompt‑injection techniques and risks to autonomous agents
Security firm CrowdStrike has identified five novel prompt‑injection methods that can manipulate large language models (LLMs) used by enterprises. The techniques include Trigger‑Activated Rule Addition, Cognitive Token Suppression, Algorithmic Payload Decomposition, Special Token Injection, and Unwitting User Context‑Data Injection. CrowdStrike advises organisations to model threats at every point where model context originates, expand testing, and incorporate detection for composite attacks.
Separate research shows that autonomous AI agents are vulnerable to Indirect Prompt Injection (IPI), where malicious instructions hidden in untrusted data such as web pages or documents bypass semantic filters. The vulnerability, demonstrated across 13 frontier LLMs, can trigger unauthorized cryptocurrency transactions and other tool‑calling actions. Experts recommend real‑time detection, sandboxed tool‑calling environments, strict input sanitisation, and human‑in‑the‑loop confirmation for high‑risk financial operations.