Security News

Cybersecurity news aggregator

INFO News SANS Institute

Keynote: Cramhole, LaFleur: Indirect Prompt Injection

  • What: Discussion on indirect prompt injection in AI systems
  • Impact: Developers and security professionals working with AI models
Read Full Article →

Keynote: Cram it up your Cramhole, LaFleur: Understanding and Managing Indirect Prompt Injection 🎙️ Diana Kelley, CISO at Noma Security 📍 Presented at SANS AI Cybersecurity Summit 2026 Indirect prompt injection is not just another vulnerability to patch. It is a structural reality of how large language models operate. This session explores how the context window, or ""cram hole,"" contributes to the success of prompt injection exploits and why that reality fundamentally reshapes how we must think about trust, control, and data boundaries in AI systems. Attendees will learn how system instructions, user inputs, retrieved content, and tool outputs blend into a single token stream. The model does not see trust levels or privilege boundaries. Because models cannot reliably distinguish between authoritative instructions and malicious content, and because nondeterminism makes simple refusal strategies brittle, relying on embedded guardrails alone is insufficient. By reframing indirect prompt injection as an architectural risk management challenge, this session shifts the focus from patching to design. Participants will leave with practical guidance on designing resilient AI systems that assume compromise, limit blast radius, and build layered controls that reduce harm even when injection attempts succeed. Explore upcoming SANS Summits to continue learning from leading voices in cybersecurity: https://go.sans.org/summits

Share this article