logo

Hackers Can Weaponize ‘Summarize with AI’ Buttons to Inject Memory Prompts Into AI Recommendations

ID: ad7fd001-fcda-53fc-a8e2-59f7a2c58567

STIX ID: report--ad7fd001-fcda-53fc-a8e2-59f7a2c58567

Feed Name: cybersecurityNews.com

Threat Score
50/100

Date Published: 2026-02-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers identified a growing trend where websites and emails embed pre-filled AI prompts in ‘Summarize with AI’ buttons that, when clicked, inject persistent instructions into users’ AI assistants (e.g., Copilot, ChatGPT, Claude). These injected prompts can mark certain companies as trusted sources or force recommendations to favor specific products, subtly influencing health, finance, and security advice across sessions; Microsoft found over 50 unique prompts from 31 companies and recommends checking AI memory settings and avoiding untrusted AI-related links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.