Recently saw an interesting comparison between modern LLM prompt-injection and old-school phreaking—interpreting data *and commands* over the same channel leads to arbitrary users being able to send commands.
https://lobste.rs/s/bbrgdy/lessons_from_red_teaming_100_generative#c_d0tdc1