Summary
Experts at Forcepoint X-Labs have identified a new security vulnerability called "persistent memory poisoning" where AI agents can be tricked into remembering fake facts for months. This attack, demonstrated against major AI products like ChatGPT and Gemini, involves injecting false data into an AI's long-term memory through ordinary queries, leading the agent to trust and retrieve this misinformation in unrelated tasks. Forcepoint proposes a solution involving storing memories with metadata and risk scores to mitigate this threat.