Adversarial Prompt Injection Payload for Evading AI-Based Detection

June 2026 Sublime Security blog, Attack Spotlight (with Sam Scholten)

Attack Spotlight breakdown of a credential phishing campaign that paired a standard fake-document-share lure with a second prompt injection payload aimed squarely at AI security scanners, using context poisoning and self-negation techniques to try to talk the model out of flagging the message.

Companion writeup: project page · Sublime blog post