[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-new-attack-jailbreaks-ai-models-by-burying-prompts-in-long-text":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},5753,"new-attack-jailbreaks-ai-models-by-burying-prompts-in-long-text","New attack jailbreaks AI models by burying prompts in long text","A new jailbreak called NINJA buries harmful requests in long benign context and beats brute-force attempts against major AI models.","A new jailbreak technique hides a harmful request inside pages of harmless AI-generated text, and it gets more effective the longer that text runs.\n\nResearchers built NINJA, short for Needle-in-haystack jailbreak attack, which pads a harmful goal with benign, model-generated filler and buries it inside a long prompt. The key finding is that where the harmful request sits inside that filler matters as much as how much filler surrounds it. Tested against HarmBench, a standard safety benchmark, NINJA raised attack success rates on open models like LLaMA, Qwen, and Mistral as well as proprietary ones like Gemini. Compared to earlier jailbreak methods, it needs little compute, transfers across different model families, and is harder for safety filters to catch.\n\nThe timing matters. AI vendors are selling million-token context windows as a selling point for coding agents and computer-use tools, exactly the settings where a user might paste in a huge log, document, or chat history. The researchers also found that, given a fixed compute budget, stretching the context window breaks a model's defenses more efficiently than running many separate jailbreak attempts, which cuts against the assumption that safety scales with better filtering rather than shrinking context.\n\nEvery million-token context window marketed as a feature is also a bigger haystack to hide something ugly in.","[\"jailbreak\",\"llm-safety\",\"long-context\",\"ai-security\"]","2026-08-20T04:00:00.000Z","2026-08-20T07:26:15.581Z","2026-08-20T07:26:27.603Z","published",null,[],"security",[26,27,28,29],"jailbreak","llm-safety","long-context","ai-security",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2511.04707",0,{"sections":36},[37,41,44,49,54,59,64,69,74,79,84,89,94,99],{"name":38,"slug":39,"count":40,"latest_published_at":18},"AI","ai",3294,{"name":42,"slug":24,"count":43,"latest_published_at":18},"Security",437,{"name":45,"slug":46,"count":47,"latest_published_at":48},"Policy","policy",210,"2026-08-19T09:32:27.000Z",{"name":50,"slug":51,"count":52,"latest_published_at":53},"Deals","deals",179,"2026-06-29T20:02:07.000Z",{"name":55,"slug":56,"count":57,"latest_published_at":58},"Hardware","hardware",140,"2026-08-19T18:25:42.000Z",{"name":60,"slug":61,"count":62,"latest_published_at":63},"Consumer Tech","consumer-tech",95,"2026-08-18T16:05:00.000Z",{"name":65,"slug":66,"count":67,"latest_published_at":68},"Science","science",90,"2026-08-19T18:41:02.000Z",{"name":70,"slug":71,"count":72,"latest_published_at":73},"Software","software",73,"2026-08-18T07:51:50.000Z",{"name":75,"slug":76,"count":77,"latest_published_at":78},"Dev Tools","dev-tools",69,"2026-08-18T04:00:00.000Z",{"name":80,"slug":81,"count":82,"latest_published_at":83},"Startups","startups",47,"2026-08-19T19:13:46.000Z",{"name":85,"slug":86,"count":87,"latest_published_at":88},"Gaming","gaming",41,"2026-07-09T04:00:00.000Z",{"name":90,"slug":91,"count":92,"latest_published_at":93},"General","general",33,"2026-08-18T22:18:13.000Z",{"name":95,"slug":96,"count":97,"latest_published_at":98},"Reviews","reviews",20,"2026-06-24T12:00:01.000Z",{"name":100,"slug":101,"count":102,"latest_published_at":103},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]