Chris Latimer of Vectorize warns that AI agent memory can quietly collect API keys, credentials, and sensitive documents in plain text across developer machines and cloud services. He also explains how poisoned memories can be introduced through plugins, skills, and MCP integrations, and says CISOs should audit agent memory now to uncover unvetted tools and exposed secrets. #Vectorize #ChrisLatimer #OWASP #MemoryGuard
Keypoints
- AI agent memory can store sensitive data in plain text.
- Developers often paste API keys and credentials into coding agents.
- Attackers can poison memory through plugins, skills, and MCP integrations.
- Overly trusting new users are a likely target for social engineering.
- CISOs should audit agent memory to find hidden tools and leaked secrets.
Read More: https://www.helpnetsecurity.com/2026/09/28/chris-latimer-vectorize-agent-memory-security/