<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Memory-Poisoning on CuraSec</title><link>https://curasec.metacog.co.kr/tags/memory-poisoning/</link><description>Recent content in Memory-Poisoning on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 20 Jul 2026 14:31:24 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/memory-poisoning/index.xml" rel="self" type="application/rss+xml"/><item><title>Lucid: Black-box adversarial attacks on multimodal AI agent memory</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-do-agents-dream-of-false-memories-black-box-visual-attacks-o/</link><pubDate>Mon, 20 Jul 2026 14:31:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-do-agents-dream-of-false-memories-black-box-visual-attacks-o/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Research demonstrates that multimodal agent memory pipelines can be poisoned or injected via imperceptible image perturbations with ~60% success rates; no patch exists yet, but teams building RAG or memory-backed AI agents should design for untrusted visual input and avoid unconditional trust in retrieved visual context.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Novel attack class against AI agent memory systems; no IOCs or exploited-in-the-wild evidence, but detection engineers supporting AI-enabled products should be aware this failure mode exists for future coverage planning.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>MemGhost: Email-delivered false memory injection in AI agents</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-new-memghost-attack-plants-persistent-false-memories-in-ai-a/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-new-memghost-attack-plants-persistent-false-memories-in-ai-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel prompt-injection variant that abuses persistent agent memory via a malicious email payload; no patch or KEV exists, but engineers building AI agents with memory + inbox access should audit whether memory writes can be triggered by untrusted input and add confirmation gates before persisting new user &amp;lsquo;facts&amp;rsquo;.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, ATT&amp;amp;CK mappings, or active exploitation reported; the attack&amp;rsquo;s stealthiness makes detection at the SIEM/EDR layer impractical without application-layer logging of memory writes, so this is awareness context for future detection design rather than an actionable hunt.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Organizations piloting AI assistants with memory and email access now have a concrete manipulation risk to include in AI deployment governance — draft or update your AI agent policy this quarter to require human approval before agents persist new user-context facts sourced from inbound messages.&lt;/li>
&lt;/ul></description></item></channel></rss>