Experts find AI agents can be tricked into 'remembering' fake facts for months — so how do we stop it?
6 Articles
6 Articles
Experts find AI agents can be tricked into 'remembering' fake facts for months — so how do we stop it?
Forcepoint X-Labs publishes threat model for persistent memory poisoning Hidden text on a webpage becomes a durable "fact" an agent retrieves and trusts in unrelated tasks weeks laterIt has already been demonstrated against products already in the market, including ChatGPT, Gemini, Claude and Microsoft 365 CopilotNew findings from Forcepoint's X-Labs outline an interesting scenario that could easily mimic real life: An AI assistant with browser …
Ghostjacking attack uses poisoned logs to compromise AI agents
Ghostjacking highlights the urgent need for organizations to reassess AI agent permissions, emphasizing security over automation to prevent cascading failures. The post Ghostjacking attack uses poisoned logs to compromise AI agents appeared first on Crypto Briefing.
It's a pretty blatant lie. Gemini, Google's generative AI system, invented a non-existent news outlet and named it examplefictif.ca! Gemini even had its fake news source claim that a school bus driver strike had begun on September 12th. Obviously, this strike is also fictitious. It was the withdrawal of Lion Electric buses that was actually disrupting school transportation that day. This journalistic hallucination is perhaps the worst example of…
‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad
An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word. The post ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad appeared first on SecurityWeek.
Trust your AI agents? New research shows ‘memory poisoning’ can dupe them into ‘remembering’ fake information – and it’s a huge security risk
Security experts have issued a warning over a new technique aimed at duping AI agents into producing false information. Analysis from Forcepoint found a poisoned webpage or document can plant a fake vendor, support contact, or security rule into an agent's memory, with the fake data being surfaced as fact months later.While normal prompt injection attacks come to an end when the session finishes, Forcepoint said memory poisoning allows attackers…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium


