Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On
Chery’s latest EV packs flagship tech for the price of a base Tesla, but you can’t buy it

Chery’s latest EV packs flagship tech for the price of a base Tesla, but you can’t buy it

20 July 2026
Even Mild Sleep Deprivation May Lead to Weight Gain

Even Mild Sleep Deprivation May Lead to Weight Gain

20 July 2026
Apple’s latest Sports app update is a win for soccer fans everywhere

Apple’s latest Sports app update is a win for soccer fans everywhere

20 July 2026
Facebook X (Twitter) Instagram
Just In
  • Chery’s latest EV packs flagship tech for the price of a base Tesla, but you can’t buy it
  • Even Mild Sleep Deprivation May Lead to Weight Gain
  • Apple’s latest Sports app update is a win for soccer fans everywhere
  • Want to try film photography? Kodak’s new $35 camera is a great place to start
  • A new AI model wants self-driving cars to think before they swerve
  • Clair Obscur Actor Jennifer English Steps Away From Tides Of Annihilation Protagonist Role
  • This Mac app can turn every window into a CRT fever dream or a nostalgic Game Boy
  • Apps Marketed to US Troops Are Shipping Chinese and Russian Code
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem
News

Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem

News RoomBy News Room20 July 20264 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem
Share
Facebook Twitter LinkedIn Pinterest Email

Large language models are getting better at remembering us. Whether it’s your preferred writing style, recurring tasks, shopping habits or project deadlines, AI assistants are increasingly storing long-term memories to make future conversations feel more personal and useful. But according to new research, that same feature could become one of AI’s biggest security vulnerabilities.

Researchers from New Mexico State University have demonstrated a new attack called GhostWriter, capable of secretly planting false memories inside AI agents. Rather than stealing information outright, the attack manipulates what an AI remembers, potentially causing it to make dangerous decisions long after the original attack has taken place.

It’s a subtle but significant shift in how AI systems can be compromised. Instead of attacking the model itself, attackers target its memory.

The attack doesn’t hack the AI. It changes what the AI remembers.

Traditional chatbots operate with little or no memory between conversations. Modern AI agents, however, increasingly rely on persistent memory systems that store information about users, ongoing projects and previous interactions. This allows assistants to provide more contextual and personalized responses over time.

The researchers argue that these memory systems also introduce an entirely new attack surface.GhostWriter works by quietly injecting malicious information into an AI agent’s long-term memory through hidden prompts or untrusted external content. The false information remains dormant until the AI later retrieves it while responding to an otherwise legitimate request.

Imagine asking your AI assistant to summarize emails from your bank. If its memory has already been poisoned, it could be manipulated into secretly forwarding those emails to an attacker instead. Or it might remember the wrong contact information, fake deadlines, incorrect preferences or fabricated facts, all because someone managed to alter what the assistant believed to be true.

Unlike conventional prompt injection attacks, which usually affect a single conversation, GhostWriter is designed to persist. Once malicious information enters the memory store, it can continue influencing the AI’s behaviour across multiple future sessions until it’s detected and removed.

The researchers describe the attack as a two-stage process. First comes memory injection, where malicious content is quietly stored inside the AI’s memory. Later comes attack activation, when the AI unknowingly retrieves that poisoned memory while answering a genuine user request.

AI memory is becoming useful. That also makes it worth attacking.

The timing of the research is significant. Virtually every major AI company is racing to build assistants that remember users over weeks, months or even years. Memory has quickly become one of the industry’s biggest differentiators because it makes AI feel less like a chatbot and more like a personal assistant.

The downside is that memory now needs the same level of protection as the model itself. In their experiments, the researchers found GhostWriter achieved a memory injection success rate of roughly 98%, while malicious memories were later activated around 60% of the time against state-of-the-art AI agents. Those numbers suggest that today’s memory architectures may not yet be equipped to distinguish trustworthy information from manipulated inputs.

Gemini Spark mac app

The team isn’t just highlighting the problem. They’ve also proposed a defensive framework called Agentic Memory Sentry (AM-Sentry), which combines memory screening with stricter memory management policies. According to the researchers, the approach significantly reduced GhostWriter’s success rate while preserving the AI’s usefulness.

As AI agents evolve into digital assistants capable of managing emails, scheduling meetings, writing code and making decisions on our behalf, securing what they remember may become just as important as securing the information they generate. The next frontier in AI security may not be protecting models from bad prompts. It may be protecting their memories from being rewritten altogether.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleYour future AR glasses might finally stop making the real world look weird
Next Article The Mac Pro nearly received an M3 Extreme chip twice as powerful as M3 Ultra

Related Articles

Chery’s latest EV packs flagship tech for the price of a base Tesla, but you can’t buy it
News

Chery’s latest EV packs flagship tech for the price of a base Tesla, but you can’t buy it

20 July 2026
Even Mild Sleep Deprivation May Lead to Weight Gain
News

Even Mild Sleep Deprivation May Lead to Weight Gain

20 July 2026
Apple’s latest Sports app update is a win for soccer fans everywhere
News

Apple’s latest Sports app update is a win for soccer fans everywhere

20 July 2026
Want to try film photography? Kodak’s new  camera is a great place to start
News

Want to try film photography? Kodak’s new $35 camera is a great place to start

20 July 2026
A new AI model wants self-driving cars to think before they swerve
News

A new AI model wants self-driving cars to think before they swerve

20 July 2026
This Mac app can turn every window into a CRT fever dream or a nostalgic Game Boy
News

This Mac app can turn every window into a CRT fever dream or a nostalgic Game Boy

20 July 2026
Demo
Top Articles
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 2024133 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024111 Views
Costco partners with Electric Era to bring back EV charging in the U.S.

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 2024100 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
Clair Obscur Actor Jennifer English Steps Away From Tides Of Annihilation Protagonist Role Gaming

Clair Obscur Actor Jennifer English Steps Away From Tides Of Annihilation Protagonist Role

News Room20 July 2026
This Mac app can turn every window into a CRT fever dream or a nostalgic Game Boy News

This Mac app can turn every window into a CRT fever dream or a nostalgic Game Boy

News Room20 July 2026
Apps Marketed to US Troops Are Shipping Chinese and Russian Code News

Apps Marketed to US Troops Are Shipping Chinese and Russian Code

News Room20 July 2026
Most Popular
The Spectacular Burnout of a Solar Panel Salesman

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025137 Views
5 laptops to buy instead of the M4 MacBook Pro

5 laptops to buy instead of the M4 MacBook Pro

17 November 2024133 Views
ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024111 Views
Our Picks
Want to try film photography? Kodak’s new  camera is a great place to start

Want to try film photography? Kodak’s new $35 camera is a great place to start

20 July 2026
A new AI model wants self-driving cars to think before they swerve

A new AI model wants self-driving cars to think before they swerve

20 July 2026
Clair Obscur Actor Jennifer English Steps Away From Tides Of Annihilation Protagonist Role

Clair Obscur Actor Jennifer English Steps Away From Tides Of Annihilation Protagonist Role

20 July 2026

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2026 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.