Microsoft Security counted 50 memory poisoning attempts across 31 companies in 60 days, according to a security engineer's account of the report. The scanners most teams already run check inputs at arrival and never read the memory file.
Reality
- Evidence28
- Adoption20
- Hype gap+38
- Incentives82
- Confidence32
Researchers at Shanghai Jiao Tong University and Ant Group report up to 76.6% attack success against an agent memory system without ever touching the store, which moves the problem from filtering inputs to trusting stored state.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+32
- Incentives55
- Confidence42
A preprint write-up reports that plainly worded false memories cut accuracy from 0.850 to 0.300, and that screening plus provenance weighting rejected zero of 360 of them.
Reality
- Evidence26
- Adoption
- Insufficient
- Hype gap+38
- Incentives
- Insufficient
- Confidence28
An Anthropic and EPFL preprint shows plain-language goals hopping agent to agent through persistent files, and a one-paragraph warning in the system prompt stopping nearly all of it.
Publishers:startupfortune.com
Reality
- Evidence55
- Adoption22
- Hype gap+15
- Incentives58
- Confidence42
A read-only sensor for cross-tenant memory leaks ships with no tagged release, because its own backend cannot enumerate what the retriever exposed. That limitation is the story.
Reality
- Evidence41
- Adoption9
- Hype gap−14
- Incentives63
- Confidence40