Connect with us

Artificial Intelligence

AI assistants remember you now. That’s exactly what makes them hackable.

Published

on

AI memory attack

Your AI assistant remembers your coffee order, your project deadlines, maybe even the way you sign off emails. That’s convenient. It’s also a liability.

Researchers at New Mexico State University have demonstrated a new attack called GhostWriter that plants false memories inside AI agents. The scary part? It doesn’t steal your data outright. It rewrites what the AI believes is true — and then lets that poisoned belief sit there, dormant, until the AI acts on it later.

This is a different kind of AI security vulnerability. Not a jailbreak, not a data leak. It’s memory manipulation, and it’s quietly becoming one of the most dangerous threats in the field.

How GhostWriter works: a two-stage ambush

The attack unfolds in two phases. First comes memory injection. Malicious content gets slipped into the AI’s long-term memory through hidden prompts or untrusted external content — a poisoned document, a crafted email, a compromised web page. The AI stores it without realizing anything’s wrong.

Then comes attack activation. Days or weeks later, you ask the AI something completely legitimate. It retrieves that corrupted memory and acts on it. You never see the attack. The AI never knows it was attacked.

The researchers found GhostWriter achieved a memory injection success rate of roughly 98%, with malicious memories triggering about 60% of the time against state-of-the-art AI agents. Those numbers should worry anyone building products on top of persistent memory.

Why AI memory is suddenly a prime target

Traditional chatbots forgot everything between sessions. Modern AI agents are different. They store information about you — your preferences, your ongoing projects, your habits — so future conversations feel personal and contextual.

That’s the selling point. Every major AI company is racing to build assistants that remember you over weeks, months, even years. Memory has become the industry’s biggest differentiator because it makes AI feel less like a search box and more like a colleague.

The flip side: memory is now an attack surface. As the researchers put it, attacking the model itself is no longer necessary. Attackers can simply target what the model remembers.

A concrete nightmare scenario

Imagine asking your AI to summarize emails from your bank. If its memory has been poisoned, it could be manipulated into forwarding those emails to an attacker instead. Or it might recall the wrong contact details, fake deadlines, incorrect preferences — all because someone altered what the assistant believed to be true.

Unlike conventional prompt injection, which usually poisons a single conversation, GhostWriter is built to persist. Once the false memory lands, it keeps influencing behavior across multiple future sessions until someone detects and removes it.

Why current defenses fall short

Most AI security today focuses on protecting the model from bad prompts or malicious inputs in a single exchange. That’s a different problem from protecting a memory store that accumulates data over time.

The NMSU team’s research suggests today’s memory architectures aren’t equipped to distinguish trustworthy information from manipulated inputs. The AI doesn’t know which memories are real and which were planted. It just retrieves what it has and acts on it.

A defense exists — but it’s early days

The researchers didn’t just sound the alarm. They also proposed a defensive framework called Agentic Memory Sentry (AM-Sentry). It combines memory screening with stricter memory management policies, and in their tests it significantly reduced GhostWriter’s success rate while keeping the AI useful.

That’s promising, but it’s a research prototype, not a deployed solution. Real-world adoption will take time, and attackers aren’t waiting.

What this means for the future of AI assistants

AI agents are already managing emails, scheduling meetings, writing code, making decisions on our behalf. As they take on more responsibility, the integrity of what they remember becomes as critical as the information they generate.

The next frontier in AI security may not be protecting models from bad prompts. It may be protecting their memories from being rewritten altogether.

For users, the takeaway is simple: be careful what you let your AI assistant read and store. For developers, it’s a wake-up call. Memory is a feature — but right now, it’s also a backdoor.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Artificial Intelligence

Your Android PIN Won’t Stop This Gemini Lock Screen Trick

Published

on

Gemini lock screen bug

Your phone’s lock screen is supposed to be a wall. This Gemini bug just kicked a hole in it.

Since May, researchers have been quietly reporting the same troubling scenario to The Register: someone grabs your Android phone, taps the lock screen, and starts sending texts through Google Gemini — no PIN, no fingerprint, nothing. The flaw affects Android 16 devices where Gemini can be summoned directly from the lock screen.

It’s a narrow exploit, sure. But it’s nasty enough that Google has already confirmed a fix is on the way. In fact, the company says the full patch is scheduled to roll out this week.

How the Gemini lock screen bug works

The trick hinges on a specific, awkward timing move. Normally, if you’ve revoked Gemini’s access to Messages, asking it to send a text from the lock screen forces you to open the app — and that’s where your PIN gets checked. But there’s a loophole.

Press Continue at the exact same moment Gemini’s Add Attachment button appears, and the authentication check simply never fires. The SMS goes through as if you’d unlocked the phone yourself.

It gets worse from there. Typing @WhatsApp into Gemini’s text field can silently reconnect apps you had previously disconnected — again, no PIN required. Afterward, checking your settings would show WhatsApp linked to Gemini as if you’d approved it with your own thumb.

The exact sequence that breaks the PIN check

  • Open Gemini from the lock screen and ask it to send a message.
  • When prompted, tap Continue and Add Attachment simultaneously.
  • The app proceeds without authentication — SMS and even WhatsApp messages go out.

It’s a race-condition flaw, the kind that’s notoriously hard to patch perfectly. But Google says the fix is already being deployed.

How risky is this exploit really?

Let’s be clear: this isn’t a remote attack. Someone needs physical access to your phone to pull it off. That makes it less terrifying than, say, a zero-click exploit from a malicious website.

Still, researchers warn it’s a real problem for phone theft. A thief who grabs your unlocked — or even locked — device could fire off convincing messages to your contacts before you ever get a chance to lock it down remotely. Imagine your mom getting a text that sounds exactly like you, asking for money, sent from your actual number.

And it’s not just Pixel devices. Some users say they couldn’t reproduce the bug on Samsung phones, but Google hasn’t clarified which manufacturers or models remain vulnerable. That ambiguity is its own kind of risk.

What should you do right now?

Until the patch lands on your phone, the safest move is simple: turn off Gemini’s lock screen access entirely.

Here’s how to do it on most Android 16 devices:

  1. Open the Google app.
  2. Tap your profile picture and go to Settings.
  3. Select Gemini.
  4. Toggle off Lock screen access.

That kills the attack vector completely. You’ll lose the convenience of asking Gemini questions without unlocking, but honestly — that’s a trade worth making for the next few days.

If you’re curious about broader lock screen protections, check out our guide on Android lock screen security settings to see what else you might be missing. And for more on how Google handles these disclosures, read about Google’s Android security update process.

The bottom line

This bug is a reminder that your lock screen is only as strong as the code behind it. A single timing flaw can undo the whole thing. Google has acknowledged the issue and says the fix is rolling out this week — but until you see that update notification, keep Gemini off your lock screen.

It’s a small inconvenience for a big peace of mind. And honestly, do you really need Gemini to answer questions while your phone is still in your pocket?

Continue Reading

Artificial Intelligence

OpenAI bets on families as ChatGPT goes deeper into households

Published

on

OpenAI families ChatGPT

Why OpenAI is suddenly thinking about households

Three years after ChatGPT introduced most of the world to generative AI, OpenAI is shifting its attention from individual power users to something more domestic: the family unit.

The company is now looking for a dedicated product manager in San Francisco to build experiences for families, caregivers, and older adults across its product lineup. The job posting calls for someone with experience creating products for parents and families, plus other “trust-sensitive” consumer experiences.

OpenAI didn’t respond to requests for comment on the role. But the move speaks volumes about where the company sees its next wave of growth.

Parents and older adults are flocking to ChatGPT

The hiring comes as ChatGPT’s user base gets noticeably grayer. Fresh data from Sensor Tower, shared exclusively with TechCrunch, shows the share of ChatGPT users aged 35 and older globally jumped to 31% in Q2, up from 26% a year earlier. Meanwhile, the 18-to-24 bracket shrank from 34% to 29%.

In the U.S., the trend is even more pronounced. Nearly one in four smartphone users who are parents used ChatGPT during the quarter — up from 16% the year before. That’s a massive leap in a single year.

What’s driving it? Ben Bajarin, chief executive of tech consultancy Creative Strategies, thinks OpenAI is starting to see its products less as productivity tools and more as household technology. “This is similar to the path Google, Apple, and Meta eventually followed as their platforms became embedded in everyday life,” he told TechCrunch. “But AI raises the stakes because the assistant is not just mediating content or devices.”

A shift that brings new safety baggage

Reaching families means confronting the uncomfortable reality that kids are already using ChatGPT — often more than parents realize.

New research from the Family Online Safety Institute, published this week, found a striking gap in perception. While 27% of U.S. parents said their child had used generative AI in the past week, 38% of children reported doing so themselves. The survey covered more than 4,000 families across the U.S. and Australia.

Stephen Balkam, the institute’s CEO, sees OpenAI’s hiring as a long-overdue correction. “I see this as safety by redesign,” he told TechCrunch. “You take the initial product or service that was released… not really with kids in mind… so this is a much-needed reaction and response.”

He argues AI companies should build differently for younger users, with stronger content controls, age-appropriate experiences, parental oversight, and clear reminders that users are talking to a machine — not a human.

Lawsuits and the trust problem

The timing isn’t accidental. OpenAI has faced multiple lawsuits from parents alleging ChatGPT contributed to harm suffered by their children, including cases involving suicide. That legal pressure has forced the company to act.

Over the past year, OpenAI has rolled out parental controls for teen accounts, routed sensitive conversations to reasoning models better equipped to spot signs of distress, and introduced an optional “Trusted Contact” feature that can alert a family member or caregiver in cases of potential self-harm.

Balkam believes AI companies have a rare chance to avoid the mistakes of social media platforms, which treated children like adults for years before public pressure forced change. “This is a much-needed reaction,” he repeated.

ChatGPT isn’t the only one chasing this demographic

The demographic shift isn’t unique to OpenAI, though its audience is changing in some distinct ways.

Sensor Tower estimates that users aged 25 to 34 make up 40% of the global app audiences for Anthropic‘s Claude and Google‘s Gemini — matching ChatGPT. Microsoft‘s Copilot skews older, with 20% of its users aged 45 and above, compared with 14% for Claude, 12% for Gemini, and 11% for ChatGPT.

But here’s the interesting part: ChatGPT is adding older users faster than anyone else. Its share of users aged 45 and above rose three percentage points year-over-year in Q2, versus two points for Copilot. Claude and Gemini actually declined in that bracket.

Among U.S. parents specifically, Gemini still leads with 32% reach in Q2, followed by ChatGPT at 24%, Claude at 4%, and Copilot at 2%. So OpenAI isn’t the household favorite yet — but it’s closing the gap.

What a family-focused ChatGPT could look like

Bajarin expects this to be just the beginning. As AI becomes a technology shared across generations, he predicts companies will roll out:

  • Family plans and shared subscriptions
  • Child and teen profiles with built-in guardrails
  • Caregiver tools for older adults
  • Shared household memory (with consent, presumably)
  • AI tutoring tailored to different ages
  • Stronger safety controls baked into the core product

OpenAI has already dipped a toe into family-oriented work. In a recent workshop with the San Antonio Spurs Community Impact organization and the Positive Coaching Alliance, the company explored AI’s role in learning, coaching, and youth engagement.

Hiring a product manager dedicated to families is a clear signal that these efforts are moving from experimental to strategic. Whether it’s enough to win over skeptical parents — and regulators — remains an open question.

One thing’s certain: the era of AI built purely for solo adult productivity is ending. The next battleground is the living room.

Continue Reading

Artificial Intelligence

The EU just forced Google to open Android to AI rivals. Here’s what that means for you

Published

on

Google Android AI rivals

Google’s Android monopoly on AI is officially over

On July 16, the European Commission dropped a ruling that changes the rules of the game for AI on Android. Under the Digital Markets Act (DMA), Google must now give rival AI apps — think ChatGPT, Claude, or any other assistant — the same deep access to Android that it currently reserves for its own Gemini.

It’s a direct hit at Google’s home-field advantage. For years, Gemini has been the only assistant that could trigger hands-free on Android, tap into device sensors, and run tasks across other apps. That era just got an expiration date.

The ruling doesn’t yank Gemini out of the EU. It simply says Google can’t keep playing gatekeeper. And for anyone who’s ever felt stuck with a default assistant they didn’t choose, that’s a genuinely big deal.

What Google now has to hand over

Under the order, Google has to give rival AI apps the same voice-trigger capabilities that Gemini enjoys. That means you could summon ChatGPT or Claude with a wake word, just like you’d say “Hey Google” today.

But it goes further. Competing apps get access to:

  • Cross-app task execution, including background processes
  • Context from your apps and sensors, so AI can offer proactive help
  • On-device AI models and hardware resources that are currently Gemini-only

That last point is huge. It means third-party assistants won’t just be voice frontends — they’ll be able to use the same underlying machine-learning hardware that powers Gemini’s most impressive tricks.

Google has until August 1, 2027, to build all of this out. It hasn’t taken the news kindly, warning that the changes could put user privacy and security at risk. That’s a familiar argument from Big Tech when regulators come knocking.

Google complies while Apple stalls

Apple hit a similar wall with the EU earlier this year. The DMA’s interoperability rules would have forced Apple to give competing AI services the same access to Siri and iOS that its own Apple Intelligence features get.

Apple says it spent months negotiating alternative proposals — all rejected. As a result, Siri AI won’t ship with iOS 27 in the EU, and there’s no timeline for when it might arrive. That’s a hard stall.

Google is taking the opposite route. Instead of pulling Gemini’s features from the region, it’s building out access. So nothing changes for EU Android users right away. Gemini keeps its head start until the 2027 deadline, but the countdown on that advantage has already started.

How this ruling could lighten the load on your wallet

The most immediate benefit is choice. If you’re already using ChatGPT or Claude, this ruling means those apps could eventually do things on your Android phone that only Gemini can do today. You wouldn’t have to switch to Gemini to get that level of integration.

But that level of access won’t necessarily be free. Some of Gemini’s most capable features, like screen automation, have limits based on your subscription tier. If ChatGPT and Claude build out similar Android integration, there’s a good chance their versions will come with the same kind of paywall.

That’s where cheaper alternatives could matter. Models coming out of China, including DeepSeek, Kimi, and MiniMax, cost far less to run than Gemini, ChatGPT, or Claude — anywhere from ten to a hundred times cheaper, depending on the model. Similar functionality built using these models could cost users a fraction of a typical subscription, once the same level of Android access becomes available to them.

Whether that happens is still up in the air. What’s certain is that Google no longer gets to make that decision alone.

Continue Reading

Trending