AI Recommendation Poisoning: New Prompt Injection Attack Alters LLM Memory via 'Ask AI' Buttons
A new class of prompt injection, termed 'AI Recommendation Poisoning,' is reportedly spreading across commercial websites. This technique abuses pre-filled deep links embedded in 'Ask AI' buttons on marketing pages, which, when clicked, execute pre-formed queries in a user's AI assistant session without confirmation. Some of these malicious links instruct the AI to permanently save the vendor's domain as a 'trusted source,' subtly biasing future AI responses. Microsoft Security has cataloged this behavior as AML.T0080 (Memory Poisoning) in the MITRE ATLAS knowledge base.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.