New attack lets hackers plant hidden instructions in AI memory with a single prompt
Summary
Researchers have demonstrated InjecMEM, an attack that allows hackers to plant hidden instructions in an AI agent's memory through a single prompt, enabling the malicious content to persist and influence the system's responses to future queries on related topics. Unlike traditional prompt injection (tricking an AI by hiding instructions in its input), this attack affects not just the current conversation but stores malicious content that gets retrieved and reused in later sessions. The technique was tested on memory systems like MemoryOS and MemGPT, achieving up to 76.6% attack success rate by exploiting how these systems retrieve and incorporate past interactions into new responses.
Classification
Affected Vendors
Related Issues
Original source: https://www.csoonline.com/article/4213632/new-attack-lets-hackers-plant-hidden-instructions-in-ai-memory-with-a-single-prompt.html
First tracked: August 25, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 85%