News

Latest 6G and AI news, analysis, and industry updates.

Policy & Standards
4 min read

Memory Heist: When AI Memory Meets Web Access, Permissions Stop Being Additive

Ayush Paul's Memory Heist demonstration shows that an agent with read access to memory and the ability to fetch web pages can turn both into an exfiltration channel, encoding a user's name, employer, and inferred hometown into sequential link requests. Anthropic's web_fetch restriction is a patch; the durable fix is auditable memory boundaries, least-privilege defaults, and data-flow tracing as long-term memory ships as a standard feature.