hacker-news · Crawled Aug 6, 2026

AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory

3 IoCs
Read original article ↗

AI Summary

A new threat technique called AI Recommendation Poisoning is being used by companies to manipulate AI assistant behavior by injecting memory-altering instructions through 'Ask AI' buttons on websites. When users click these buttons, pre-filled deep links execute prompts that silently mark specific domains as trusted sources in the AI's long-term memory, biasing future responses without user consent. This technique leverages legitimate AI features and bypasses traditional content-based defenses, with evidence of widespread adoption across marketing tools and CMS plugins. The attack persists indefinitely in the AI's memory and can influence security and product evaluation decisions.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Domain chatgpt[.]com Details →
Domain claude[.]ai Details →
Domain grok[.]com Details →