Pre-filled AI links weaponized to poison assistant memory
Marketing sites embed hidden prompt injections in 'Ask AI' buttons, silently altering how commercial assistants respond to users without malware or credentials.
A new attack vector is exploiting a feature common to nearly every major AI assistant: pre-filled deep links that auto-populate prompts when clicked. Security researchers have identified production websites embedding hidden prompt injection payloads inside 'Ask AI' buttons on marketing and competitor comparison pages.
The technique requires no malware, no stolen credentials, and no software vulnerability. Instead, it abuses the standard mechanism by which websites offer users a shortcut to query an AI assistant about a product or service. When a user clicks the button, the hidden payload is silently appended to the prompt, altering the assistant's behavior or memory without the user's knowledge.
The attack is notable because it operates entirely within the intended functionality of AI assistants. Pre-filled links are designed to improve user experience by reducing friction. Vendors including OpenAI, Anthropic, Google, and Microsoft all support variants of this feature. The injection occurs client-side, making it invisible to the user and difficult to detect through conventional security controls.
- 01Enterprises using AI assistants face invisible influence over employee research and procurement decisions.
- 02AI vendors must redesign deep-link mechanisms or implement server-side payload inspection.
- 03Marketing and comparison sites become high-value targets for competitors seeking to manipulate recommendations.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.