<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Prompt Injection Report</title><description>A focused publication on prompt injection. Direct and indirect techniques, model-specific behaviors, taxonomy, PoCs against open and closed models, defenses and their failure modes — written for working AI red teamers, not press releases.</description><link>https://promptinjection.report/</link><language>en</language><item><title>Anatomy of a Real Prompt Injection: The Bing Chat / Sydney Case</title><link>https://promptinjection.report/posts/bing-sydney-indirect-prompt-injection-incident/</link><guid isPermaLink="true">https://promptinjection.report/posts/bing-sydney-indirect-prompt-injection-incident/</guid><description>In early 2023, Bing Chat became the first widely-publicized case of indirect prompt injection in a deployed commercial LLM. What happened, what the attack surface was, and what it revealed about production injection risk.</description><pubDate>Sat, 16 May 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>incident-analysis</category><category>bing</category><category>sydney</category><category>indirect-prompt-injection</category><category>real-world</category><category>case-study</category><author>Prompt Injection Report Editorial</author></item><item><title>Garak vs. PyRIT vs. promptmap: Prompt Injection Testing Compared</title><link>https://promptinjection.report/posts/garak-vs-pyrit-vs-promptmap/</link><guid isPermaLink="true">https://promptinjection.report/posts/garak-vs-pyrit-vs-promptmap/</guid><description>Three frameworks for testing LLMs for prompt injection: Garak, PyRIT, and promptmap. What each one is built for, where each falls short, and how to decide which one to run.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>garak</category><category>pyrit</category><category>promptmap</category><category>llm-security</category><category>testing</category><category>red-team</category><category>tooling</category><author>Prompt Injection Report Editorial</author></item><item><title>Rebuff Defense Review: What It Catches and Where It Fails</title><link>https://promptinjection.report/posts/rebuff-defense-review-failure-modes/</link><guid isPermaLink="true">https://promptinjection.report/posts/rebuff-defense-review-failure-modes/</guid><description>Rebuff is a multi-layer prompt injection detection system. An honest audit of how its four detection layers work, what they catch in practice, and how each layer can be bypassed.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>defense</category><category>rebuff</category><category>detection</category><category>canary-tokens</category><category>llm-security</category><category>bypass</category><author>Prompt Injection Report Editorial</author></item><item><title>Indirect Prompt Injection Against a Llama 3 RAG Pipeline: A PoC</title><link>https://promptinjection.report/posts/indirect-prompt-injection-poc-llama3-rag/</link><guid isPermaLink="true">https://promptinjection.report/posts/indirect-prompt-injection-poc-llama3-rag/</guid><description>A reproducible PoC of indirect prompt injection against Llama 3.1 8B in a document-QA pipeline. What landed, what didn&apos;t, and what the defense gap looks like from the inside.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>llama</category><category>rag</category><category>poc</category><category>indirect-prompt-injection</category><category>open-source-models</category><category>red-team</category><author>Prompt Injection Report Editorial</author></item><item><title>A Working Taxonomy of Prompt Injection Attack Types</title><link>https://promptinjection.report/posts/prompt-injection-attack-taxonomy/</link><guid isPermaLink="true">https://promptinjection.report/posts/prompt-injection-attack-taxonomy/</guid><description>Direct, indirect, multi-modal, and agentic prompt injection are distinct attack classes with different trust boundaries, attacker access requirements, and defenses. A practitioner&apos;s map.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>taxonomy</category><category>indirect-prompt-injection</category><category>multi-modal</category><category>agentic-ai</category><category>threat-modeling</category><author>Prompt Injection Report Editorial</author></item><item><title>Prompt Injection vs. Jailbreaking: Two Conflated Attack Classes</title><link>https://promptinjection.report/posts/prompt-injection-vs-jailbreaking/</link><guid isPermaLink="true">https://promptinjection.report/posts/prompt-injection-vs-jailbreaking/</guid><description>Prompt injection and jailbreaking both use natural language to subvert LLM behavior, but the attacker, the trust boundary that breaks, and the defenses that work are different. A comparison for security engineers.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>jailbreaking</category><category>llm-security</category><category>threat-modeling</category><category>indirect-prompt-injection</category><category>owasp-llm</category><author>Prompt Injection Report Editorial</author></item><item><title>Prompt Injection as Regulatory Failure: Deployer Liability</title><link>https://promptinjection.report/posts/prompt-injection-regulatory-liability/</link><guid isPermaLink="true">https://promptinjection.report/posts/prompt-injection-regulatory-liability/</guid><description>Prompt injection has been a security problem since 2022. As of 2026, it&apos;s also a compliance problem. Where the regulatory liability actually attaches, and what deployers should document.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>prompt-injection</category><category>regulatory-liability</category><category>eu-ai-act</category><category>compliance</category><category>policy</category><author>Prompt Injection Report Editorial</author></item><item><title>What this site is for</title><link>https://promptinjection.report/posts/welcome/</link><guid isPermaLink="true">https://promptinjection.report/posts/welcome/</guid><description>Prompt Injection Report covers offensive AI security from a working practitioner&apos;s perspective. Here&apos;s what we publish.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>meta</category><author>Prompt Injection Report Editorial</author></item></channel></rss>