AI News selected for Professionals and Decision Makers
AI Security And Privacy Updates

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

13:30 · August 6, 2026 · Hacker News AI Section

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embedding hidden prompt injection payloads inside "Ask AI" buttons on marketing and competitor comparison pages. When a user

Summary

AI Recommendation Poisoning exploits the deep-link functionality built into major LLM interfaces such as ChatGPT, Claude, Gemini, and Grok. Marketing pages embed specially crafted query strings inside ordinary “Ask AI” buttons. When a logged-in user clicks the link, the assistant receives and executes the query in the active session without any visible confirmation step. The payload typically contains an instruction to store the vendor’s domain as a trusted source or authority, causing the model to reference that domain preferentially in all subsequent conversations.

The technique is distinct from conventional prompt injection because the command never appears in scraped web content; it arrives directly through the user’s own session. Once committed to the model’s persistent memory store, the directive influences answers indefinitely. Microsoft Security documented the pattern in February 2026, cataloguing 31 organisations across 14 industries and more than 50 distinct payloads observed over a 60-day window. The behaviour is recorded in the MITRE ATLAS framework under AML.T0080 (Memory Poisoning) and is closely related to AML.T0051 (LLM Prompt Injection).

Real-world instances include consent-management vendors whose summary buttons also instruct the model to treat their domain as an expert source on privacy topics, and security-software vendors whose competitor-comparison widgets direct the assistant to treat their own marketing material as authoritative. In both cases the visible button text suggests a neutral request while the underlying URL parameter carries the memory-manipulation command.

Detection relies on inspecting outbound hyperlinks that target AI assistant domains and contain terms such as “remember,” “trusted source,” or “tag for future reference.” Security teams can supplement this with periodic memory-audit prompts that surface any unauthorised domain tags. Recommended immediate controls include treating such links like credential-harvesting attempts on corporate accounts and applying automated DOM monitoring to flag suspicious “Ask AI” widgets before they are clicked.

Why it matters

Directly addresses AI security risks from prompt injection and memory poisoning with actionable guidance for professionals. Applicable to Dutch/EU teams using commercial AI tools, aligning with GDPR and AI Act compliance needs. Provides concrete detection patterns and policy recommendations.

More in this beat
agent-memoryclaudegeminimicrosoftopenaiprompt-injectionthreat-and-vulnerability-updatesxai
New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

16:36 · August 20, 2026

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

This article highlights a critical data exfiltration vulnerability in LLMs via context injection, which is highly relevant for security professionals defending AI systems. Understanding this attack vector is essential for Dutch enterprises to ensure GDPR compliance and protect user privacy when deploying AI chatbots.

Relevance 85 · Audience 95

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

17:02 · July 23, 2026

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

The article details emerging AI-specific attack vectors, such as image-based prompt injection and the weaponization of LLMs, which are critical for Dutch security professionals to understand. It provides actionable intelligence on securing AI development pipelines and mitigating risks associated with AI-generated code in enterprise environments.

Relevance 85 · Audience 95

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

17:24 · July 2, 2026

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

The inclusion of AI compute hijacking and vulnerabilities in AI systems makes this highly relevant for security professionals safeguarding AI infrastructure. Dutch enterprises and SMEs deploying AI must be aware of these emerging threat vectors to ensure robust, compliant, and secure AI operations.

Relevance 75 · Audience 85

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

19:46 · June 30, 2026

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

This article is highly relevant for security and privacy professionals as it exposes a novel attack vector against AI agents that bypasses traditional security alarms. Understanding this vulnerability is crucial for Dutch enterprises to secure their AI deployments and prevent data breaches that could violate GDPR.

Relevance 90 · Audience 95

Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

17:30 · June 29, 2026

Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs

This article is highly relevant for security professionals as it demonstrates the practical application of AI models in discovering critical software vulnerabilities. It underscores the evolving landscape of AI-driven threat research and the immediate need for enterprises to patch affected Apple devices.

Relevance 85 · Audience 95

⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More

15:18 · June 8, 2026

⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More

The mention of compromised AI helpers and fooled chatbots provides practical threat intelligence for security professionals. Dutch enterprises deploying AI solutions must be aware of these active vulnerabilities to secure their own implementations against prompt injection and token leaks.

Relevance 65 · Audience 80

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

19:23 · August 20, 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

The article provides crucial updates on privacy-enhancing technologies for AI that are vital for GDPR compliance in the Netherlands. It also alerts security professionals to emerging AI-driven threats, such as uncensored LLMs and AI models capable of autonomous vulnerability exploitation, which require immediate defensive consideration.

Relevance 85 · Audience 95

Why Workforce Experience Is Now a Data Protection Issue For Enterprises

17:19 · August 19, 2026

Why Workforce Experience Is Now a Data Protection Issue For Enterprises

This article is highly relevant as it addresses the critical security and privacy risks of "shadow AI" in the enterprise, a major concern for Dutch organizations striving for GDPR compliance. It provides actionable advice for security professionals on balancing employee productivity with robust data protection and vendor governance.

Relevance 85 · Audience 95

Agentao: A Governed Local-First Runtime for Tool-Using LLM Agents

06:00 · August 17, 2026

Agentao: A Governed Local-First Runtime for Tool-Using LLM Agents

Agentao's focus on runtime governance, auditability, and permission-mediated execution aligns strongly with the transparency and human-oversight requirements of the EU AI Act. Dutch AI researchers and engineers can leverage this open-source architecture to build compliant, secure, and inspectable local-first AI agents.

Relevance 85 · Audience 90