logo

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

ID: 4a6182f0-2d24-5b72-8cbd-3c7923db2e0c

STIX ID: report--4a6182f0-2d24-5b72-8cbd-3c7923db2e0c

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

This report summarizes a research paper demonstrating "stealth memory injection," an email-based technique (implemented by a tool called MemGhost) that can cause personal AI assistants which read email and write persistent memory to silently store false information; lab tests showed high success rates in background-mode runs against several agent frameworks. The authors document how the attacks evade input filters and hardened models, outline related prior incidents (EchoLeak, SpAIware), and recommend mitigations such as provenance tagging, user confirmation and separating untrusted email readers from memory-writing agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.