Prompt Injection Attacks Explained With Real Examples and Defences
This article provides an in-depth explanation of prompt injection attacks against LLM-based systems, covering both direct and indirect attack types. It uses real-world examples, such as the EchoLeak vulnerability (CVE-2025-32711), which achieved zero-click data exfiltration through Microsoft 365 Copilot, to demonstrate how hidden instructions embedded in emails, documents, or web pages can override an AI assistant's intended behavior. The article explains why prompt injection is fundamentally difficult to fix, noting that models cannot reliably distinguish between trusted system instructions and untrusted content once they are concatenated in the same context window. Defence recommendations include architectural separation of instructions from data using structural delimiters, input sanitization, output scanning, and restricting agent capabilities to limit the blast radius of a successful injection. https://clearpathsecurity.co.uk/prompt-injection-attacks-explained-with-real-examp...