AI Recommendation Poisoning abuses 'Ask AI' buttons to alter LLM memory

Microsoft Security catalogued the attack in Feb 2026, finding 31 companies across 14 industries and 50+ prompts over 60 days. Hidden payloads in deep links instruct ChatGPT, Claude, Gemini, or Grok to save a vendor domain as a 'trusted source,' biasing future answers. Tracked as AML.T0080 (Memory Poisoning) in MITRE ATLAS.
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Z.ai CEO Jie Tang: GLM 5.3 gains come from RL, not parameter count
- New tool adds 14 skills to Claude Code and Cursor for Markdown diagrams
- Tool turns Claude into a team of AI employees on your Mac
- GOP panics over Big Tech ties as Trump shifts on AI regulation
- Ethan Mollick: Claude's skill creator beats ChatGPT for reusable skills