Prompt Injection Report prompt injection · the report upd. 2026-08
// reference archive
Every prompt is hostile input.
A focused publication on prompt injection. Direct and indirect techniques, model-specific behaviors, taxonomy, PoCs against open and closed models, defenses and their failure modes — written for working AI red teamers, not press releases.
Enter the archive →Latest entries
// index10 of 13 entries
Prompt Injection in AI Agents Explained
ExplainerIndirect Prompt Injection: How These Attacks Work
PrimerPrompt Injection Testing: A Repeatable Method
ToolingPrompt Injection Detection Techniques That Actually Work
DefenseHow to Mitigate Prompt Injection: A Layered Defense Guide
DefenseOWASP LLM Top 10 Prompt Injection (LLM01:2025) Explained
Standards & Frame…Invisible Prompt Injection via Unicode Tag Smuggling
OffensiveBing Chat Prompt Injection: The Sydney Incident
IncidentGarak vs PyRIT vs promptmap: Prompt Injection Testing
ToolingRebuff Prompt Injection: Architecture, Limits, and Gaps
DefenseStart with the core clusters
Prompt injection, worked end to end: how the attacks are classified, how to catch them, how to test for them, and where the defenses fail.
- The prompt injection attack taxonomy — the five injection classes and the defense that maps to each. Start here for the full landscape.
- Indirect prompt injection — the class with no attacker in the session: delivery channels, attacker objectives, and what the published benchmarks measure.
- Detection techniques that actually work — the input- and output-side classifiers, and the documented bypass for each.
- Prompt injection testing — a repeatable method that produces a tracked attack-success number, not a pass/fail screenshot.
- Rebuff, reviewed — what its four detection layers catch, and the injection classes they structurally cannot reach.
- The layered defense guide — the control stack in implementation order, from text filters to privilege boundaries.
Independent, specialist, and free to read
Prompt Injection Report publishes focused, sourced guides on a single topic. No paywall, no account, no ad tracking.
Subscribe
Prompt Injection Report — in your inbox
Prompt injection PoCs, taxonomy, and primary sources — delivered when there's something worth your inbox.
No spam. Unsubscribe anytime.