Severity: HighResearchPrompt injection
MemGhost Attack Exploits AI Agent Memory via Email-Injected False Data
Global
Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.
A new attack called MemGhost allows adversaries to inject false persistent memories into AI agents through a single email, causing the agent to save and act on inaccurate information about users in future sessions. The attack manipulates the agent's stored knowledge while concealing the tampering, resulting in silent degradation of response accuracy without user or operator awareness.
What to do
Enforce strict input validation and anomaly detection on all external data ingestion points into agent memory stores.
Mapped framework pillars
Sources
#AI agent#memory poisoning#prompt injection#persistence#data integrity#inbox access
