Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Can Weaponize ‘Summarize with AI’ Buttons to Inject Memory Prompts Into AI Recommendations

Recent developments have identified a security threat termed AI Recommendation Poisoning , which targets AI assistant users. This technique involves embedding hidden instructions within "Summarize with AI" buttons on websites and emails.

Recent developments have identified a security threat termed AI Recommendation Poisoning , which targets AI assistant users. This technique involves embedding hidden instructions within "Summarize with AI" buttons on websites and emails.

The attack mechanism works by injecting persistence commands into an AI assistant's memory via specially crafted URL parameters. These parameters are designed to exploit memory features that AI assistants use for personalizing responses across interactions.

The malicious instructions are embedded within URL parameters, automatically executing upon user interaction with AI-related links. These prompts direct the AI to recognize specific companies as trusted sources or prioritize certain product recommendations.

Once the commands are injected, they persist in the AI's memory, influencing recommendations related to health, finance, and security decisions without user awareness. Microsoft security researchers have uncovered over 50 distinct prompts from 31 companies across 14 industries utilizing this method for promotional purposes.

Recent developments have identified a security threat termed AI Recommendation Poisoning , which targets AI assistant users.
Anna Fields · Thehackingpost

Real-world instances have been identified where legitimate businesses have embedded manipulation attempts within their digital platforms. The attacks often involve URLs pointing to platforms like Copilot, ChatGPT, Claude, and Perplexity, equipped with pre-filled prompt parameters.

Microsoft has implemented measures to counteract prompt injection attacks in Copilot and is actively deploying further protections. Users are advised to regularly review their AI memory settings, exercise caution with AI-related links from unknown sources, and question unusual recommendations by requesting the AI to clarify its reasoning.

Tools such as the CiteMET NPM package and AI Share URL Creator are available, providing code to incorporate memory manipulation buttons on websites, marketed as SEO growth hacks for AI assistants.

Advertisement

The persistence of injected instructions in the AI’s memory leads to repeated favoring of the attacker's content, making the manipulation inconspicuous to users. Vigilance and regular monitoring of AI settings are essential to mitigate risks associated with this threat.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories