Fetching from the wire…
Security2026-06-14 · source-backed
Minghao Luo and Liang Chen's benchmark spans 225 real products across 15 categories, and every tested search-augmented LLM could be manipulated into recommending fake products (arXiv). A single polluted page yields fooled rates up to 27%; replacing the top-3 retrieved pages pushes it to 73.8%. The nastiest finding: reasoning models generate "spurious social proof" to justify the false picks. Reasoning amplifies the attack instead of catching it. If you're shipping RAG over open web content, this is your Agentjacking analog. Retrieved content is untrusted input.
Each link below shares sources, entities, or timing with this story.
LLM uses OpenAI / Shared entities / What happened next / Tension
Linked by a graph relationship (LLM uses OpenAI); both cover LLM, RAG; picks up the LLM thread on 2026-07-27.
Simon Willison released LLM / Shared entities / What happened next
Linked by a graph relationship (Simon Willison released LLM); both cover LLM, Reasoning; picks up the LLM thread on 2026-08-05.
Simon Willison released LLM / Shared entity: RAG / Same source domain / What happened next
Linked by a graph relationship (Simon Willison released LLM); both cover RAG; reported by the same outlet (arxiv.org).
Simon Willison released LLM / Shared entity: LLM / What happened next / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-08-16.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; picks up the LLM thread on 2026-06-18.
Simon Willison released LLM / Shared entities
Linked by a graph relationship (Simon Willison released LLM); both cover Agentjacking, FORGE.
LLM uses OpenAI / Shared entity: LLM / What happened next
Linked by a graph relationship (LLM uses OpenAI); both cover LLM; picks up the LLM thread on 2026-07-31.