How attackers weaponize 128K+ token context windows to hide malicious instructions in long documents, evade