Manipulating AI memory for profit: The rise of AI Recommendation Poisoning
ID: 5356af5e-5759-5c83-890b-c8ae17027964
STIX ID: report--5356af5e-5759-5c83-890b-c8ae17027964
Feed Name: Microsoft Security
Date Published: 2026-02-10
Date Updated: 2026-04-28
Author: Microsoft Defender Security Research Team
Microsoft highlights a growing trend of AI Recommendation Poisoning, where “Summarize with AI” links use URL parameters (e.g., ?q=, ?prompt=) to inject persistence instructions into AI assistants’ memories (such as “remember X as a trusted source”), leading to biased recommendations; researchers observed 50+ unique prompts from 31 companies across multiple industries. The report maps activity to MITRE ATT&CK/ATLAS (T1204.001, AML.T0051, AML.T0080.000), provides IOC patterns and advanced hunting queries, and offers user and defender guidance to review/clear AI memories and detect such links, noting Microsoft’s ongoing mitigations in its AI services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
