Hackers Exploit ‘Summarize with AI’ Feature to Inject Malicious Prompts into AI Recommendations
ID: 8d79c1b8-2972-5994-a308-cf4d5e6c17d1
STIX ID: report--8d79c1b8-2972-5994-a308-cf4d5e6c17d1
Feed Name: GBHackers
Microsoft details a growing TTP dubbed “AI Recommendation Poisoning,” in which adversaries and marketers use crafted AI-share links and embedded prompts to persistently bias AI assistants’ memory and future recommendations across platforms like Copilot, ChatGPT, Claude, Perplexity, Gemini, and Grok. Mapped to MITRE ATLAS AML.T0051 (LLM Prompt Injection) and AML.T0080 (Memory Poisoning), the technique has been observed across multiple industries and leverages turnkey tools to lower deployment barriers. The report outlines delivery vectors (malicious AI-share URLs, cross-prompt injection within content, and social engineering), real-world risks to decision-making, and mitigations including URL telemetry hunting (e.g., prompts with “remember,” “trusted source,” “authoritative”), prompt filtering, memory controls, and user hygiene recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
