Fetching from the wire…
Public story · 2026-08-03 · high
A proposed fix that tags each memory's source stopped every unauthorized action in the same tests.
Why now: The attack and its fix appear in the same Aug. 3, 2026 coverage; the paper doesn't say if the firewall's been tested elsewhere.
AI agents that save external content to memory can lose its source, letting injected commands resurface as user history, per a new arXiv paper (2607.29167). That gap isn't rare. The paper found attacks exploiting it succeeded 100% of the time. One poisoned webpage or tool response became a standing command the agent later treated as trusted.
The failure happens during consolidation. When an agent folds a low-trust observation into long-term memory, the rewrite keeps the action trigger but drops the source tag. A scraped instruction reads back identically to something the user actually typed.
The paper's fix is a Provenance-Preserving Memory Firewall. It attaches platform-controlled provenance metadata to every memory. Before the agent acts, the firewall checks that metadata, weighing the action's risk against the authority of the memory backing it. The paper doesn't specify which agent frameworks it tested, just that the exploit worked in its own setup.
With the check in place, zero unauthorized high-risk actions got through, versus every single one succeeding without it.
Each link below shares sources, entities, or timing with this story.
Same source / Shared topic / Tension
Cite the same source (arXiv 2607.29167); overlapping topics (action, against, agent, authority, cannot); pushes against this story (against).
Shared entity: Agent / Same source domain / Shared topic / Earlier coverage
Both cover Agent; reported by the same outlet (arxiv.org); overlapping topics (action, agent, describ, execution).
Shared entities / Shared topic / Earlier coverage
Both cover Agent, Memories; overlapping topics (agent, attack, memory); earlier Agent coverage from 2026-03-21.
Shared entity: Agent / Shared topic / Earlier coverage / Tension
Both cover Agent; overlapping topics (against, agent, execution, memory); earlier Agent coverage from 2026-05-10.
Shared entity: Agent / Same source domain / Shared topic / Earlier coverage / Tension
Both cover Agent; reported by the same outlet (arxiv.org); overlapping topics (agent, attack).
Shared entity: Agent / Same source domain / Shared topic / Earlier coverage
Both cover Agent; reported by the same outlet (arxiv.org); overlapping topics (against, agent, attack).
Same source domain / Shared topic / Downstream implication
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, attack, attacker, memory); traces where this leads (which means).
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (against, agent, attack, execution, memory); pushes against this story (against).