Index live· 1,284 files · 148 editions
ForensicPost

Search the index

8 results
Try
Results for “Prompt injection”Newest first
26-0531
File

Research Describes Prompt Injection Developing a Multistep Kill Chain

Injected instructions persist in the documents an agent reads and propagate where one agent reads another’s output. No filesystem required.

ResearchPrompt injection chainCloudResearch
Sev 3TargetMulti-agent deploymentsActorResearch
26-0509
File

Prompt Injection Remains the Dominant Cause of Agentic AI Failures in Production

SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.

MultiplePrompt injectionCloudAI agents
Sev 4TargetAgentic AI deploymentsActorMultiple
26-0303
File

Financial Services AI Agent Disclosed Internal Pricing for Three Weeks

No anomalous login, no unusual volume, no malformed input — just a grammatical question, for three weeks.

UnattributedPrompt injectionFinanceAI agents
Sev 3TargetFinancial services AI agentActorUnattributed
25-1224
File

Promptware Research Traces a Shift to Multi-Stage Campaigns

Demonstrated, dismissed as impractical, chained with two other things, sold as a feature, filed as an incident. Every technique here took that route.

MultiplePrompt injectionCloudAnalysis
Sev 4TargetAI agent deploymentsActorMultiple
25-1118
File

Researchers Documented Indirect Prompt Injection Planted in Web Content

A person reading a hostile page is not compromised by reading it. An agent is deciding what to do next on the basis of what the page says.

UnattributedIndirect prompt injectionCloudExploitation
Sev 4TargetBrowsing AI agentsActorUnattributed
25-0721
File

Ninety-four per Cent of Tested Agents Could Be Hijacked by What They Read

Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.

MultiplePrompt injectionCloudExploitation
Sev 4TargetAI agent deploymentsActorMultiple
25-0503
File

The Agent Is Authorised as You, and Nobody Asked Whether It Should Be

The system correctly identifies who the request is from. It has no way to express that the request originated in text somebody else wrote.

MultiplePrompt injectionCloudMethod
Sev 4TargetAgent authorisation modelsActorMultiple
25-0224
File

A Language Model Cannot Distinguish Code From Content

Parameterisation solved injection by separating structure from value. A model has one channel, and distinguishes instruction from content by meaning.

MultiplePrompt injectionCloudMethod
Sev 4TargetLanguage model systemsActorMultiple
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging