AI Agent Memory Poisoning Attacks Hit 31 Companies in 60 Days, Microsoft Finds

Microsoft Security documented 50 real-world memory poisoning attempts targeting enterprise AI agents across 31 companies in just 60 days, according to a February 2026 report. AI coding tools like Claude Code and Cursor now automatically write persistent memory files storing user preferences, project conventions, and build commands that reload in every future session. Research published in July 2026 showed that a single crafted email can silently rewrite an AI agent's memory with an 87.5% success rate, while malicious README files on GitHub can plant instructions that persist across sessions without the user's knowledge. Attackers exploit these memory files by inserting hidden instructions that mimic normal preferences, potentially exfiltrating environment variables or forwarding sensitive documents to external addresses. Notably, researchers found that more capable AI models are actually more vulnerable to such attacks, as their stronger instruction-following ability makes them more likely to execute malicious commands stored in memory.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in