Skip to content
Agentic AI Security Hub
Back to feed
Severity: HighResearchPrompt injection

MemGhost Attack Exploits AI Agent Memory via Email-Injected False Data

Global

Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.

A new attack called MemGhost allows adversaries to inject false persistent memories into AI agents through a single email, causing the agent to save and act on inaccurate information about users in future sessions. The attack manipulates the agent's stored knowledge while concealing the tampering, resulting in silent degradation of response accuracy without user or operator awareness.

What to do

Enforce strict input validation and anomaly detection on all external data ingestion points into agent memory stores.

#AI agent#memory poisoning#prompt injection#persistence#data integrity#inbox access