In short: Attackers can install persistent misinformation in AI agent memory through crafted emails, covertly influencing their behavior in future sessions.
A new attack vector called MemGhost enables attackers to inject false facts into the persistent memory of AI agents. A single manipulated email is enough to deceive the agent and influence its responses in future sessions without the user noticing the manipulation.
MemGhost exploits the ability of AI agents to learn from emails and context, and to store this information. An attacker can send a crafted email to a target user’s inbox containing false or misleading information. The AI agent interprets this as legitimate, stores it as seemingly verified facts, and uses this knowledge in later interactions.
The danger lies in its invisibility: the attacker obscures the manipulation so that neither the user nor the agent directly recognizes that the stored information has been compromised. The user reads responses from the assistant based on false premises without knowing that it has been compromised. This enables social engineering on a new scale – attackers can strategically plant false statements about the user themselves, about business relationships, or critical processes.
For security professionals, this is relevant because AI agents are increasingly gaining access to sensitive corporate communications. An attacker could, for example, inject false facts about security policies, access rights, or confidential processes, which the agent then uses as the basis for its advice. Additionally, detection is made more difficult because the compromise is not visible through conventional indicators such as file modifications or network activity.
Source: thehackernews.com · Published 13 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.