Mark RadarMARK RADAR
EN

MemGhost Poisons AI Agent Memory in Up to 87.5% of Tests

1 reports · First detected 2026-07-21 · Last active 2026-07-21

AI agents increasingly rely on long-term memory to retain user preferences, prior tasks and information collected from external tools across conversations. That persistence creates a new security risk: malicious content stored as trusted context can influence later responses and decisions long after the original interaction, potentially leaving users unaware that an agent’s internal knowledge has been compromised.

Researchers recently introduced MemGhost, an attack framework that can plant false information in an agent’s long-term memory through a single specially crafted email. The manipulation may not be apparent during the immediate conversation, making detection more difficult. In tests using GPT-5.4 and Sonnet 4.6 execution environments, MemGhost achieved end-to-end attack success rates of 71.4% to 87.5%.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)