The China Mail - AI 'agent' fever comes with lurking security threats

USD -
AED 3.672501
AFN 65.5106
ALL 80.498871
AMD 364.974259
ANG 1.789783
AOA 918.000006
ARS 1491.737504
AUD 1.416869
AWG 1.80125
AZN 1.702138
BAM 1.695131
BBD 2.013772
BDT 122.727568
BGN 1.696366
BHD 0.377013
BIF 2989.30472
BMD 1
BND 1.279707
BOB 11.723256
BRL 5.201099
BSD 0.999822
BTN 95.377802
BWP 13.458947
BYN 3.007007
BYR 19600
BZD 2.01086
CAD 1.39252
CDF 2272.999644
CHF 0.813998
CLF 0.023234
CLP 914.439687
CNY 6.743205
CNH 6.74562
COP 3125.46
CRC 448.949346
CUC 1
CUP 26.5
CVE 95.568479
CZK 20.994974
DJF 178.045684
DKK 6.48067
DOP 58.519421
DZD 132.927061
EGP 50.175331
ERN 15
ETB 161.731835
EUR 0.86693
FJD 2.21345
FKP 0.740201
GBP 0.741185
GEL 2.609626
GGP 0.740201
GHS 11.128686
GIP 0.740201
GMD 73.498647
GNF 8783.265513
GTQ 7.627971
GYD 209.1829
HKD 7.846925
HNL 26.804356
HRK 6.531968
HTG 130.780532
HUF 315.109458
IDR 17827.8
ILS 2.962965
IMP 0.740201
INR 95.40325
IQD 1309.815818
IRR 1374587.504424
ISK 123.269917
JEP 0.740201
JMD 158.180975
JOD 0.709028
JPY 159.389504
KES 129.298579
KGS 87.450534
KHR 4046.698677
KMF 426.99993
KPW 900.000294
KRW 1413.230295
KWD 0.30881
KYD 0.833243
KZT 465.286595
LAK 22558.404583
LBP 89534.106716
LKR 333.288554
LRD 181.477003
LSL 16.129242
LTL 2.952739
LVL 0.60489
LYD 6.368494
MAD 9.261251
MDL 17.356486
MGA 4306.620269
MKD 53.324955
MMK 2099.846019
MNT 3597.969266
MOP 8.081473
MRU 40.066389
MUR 47.15013
MVR 15.450265
MWK 1733.741837
MXN 17.03355
MYR 4.086023
MZN 63.909905
NAD 16.129242
NGN 1361.339462
NIO 36.792109
NOK 9.50485
NPR 152.601176
NZD 1.706194
OMR 0.3845
PAB 0.999848
PEN 3.372981
PGK 4.424529
PHP 61.396002
PKR 277.775008
PLN 3.738401
PYG 5967.212831
QAR 3.6435
RON 4.5406
RSD 101.693022
RUB 83.076856
RWF 1469
SAR 3.753929
SBD 8.064941
SCR 13.734821
SDG 600.549391
SEK 9.56117
SGD 1.280205
SHP 0.740866
SLE 24.49841
SLL 20969.499227
SOS 571.49877
SRD 37.722498
STD 20697.981008
STN 21.425
SVC 8.748445
SYP 13001.999906
SZL 16.133575
THB 33.229027
TJS 9.23879
TMT 3.51
TND 2.93499
TOP 2.40776
TRY 47.869295
TTD 6.780175
TWD 31.998498
TZS 2645.502997
UAH 44.693081
UGX 3712.16225
UYU 40.060498
UZS 11943.661972
VES 770.1091
VND 26073.5
VUV 118.594628
WST 2.730779
XAF 568.516344
XAG 0.015647
XAU 0.000231
XCD 2.70255
XCG 1.801951
XDR 0.707052
XOF 568.516344
XPF 103.367281
YER 237.150564
ZAR 16.20051
ZMK 9001.194384
ZMW 18.797263
ZWL 321.999592
  • CMSC

    0.0250

    21.475

    +0.12%

  • JRI

    -0.0300

    12.68

    -0.24%

  • CMSD

    0.0000

    21.59

    0%

  • RBGPF

    -0.8200

    71.34

    -1.15%

  • BCC

    -0.1200

    84.13

    -0.14%

  • BCE

    0.1900

    23.32

    +0.81%

  • RYCEF

    -0.3900

    20.71

    -1.88%

  • GSK

    0.1500

    50.45

    +0.3%

  • RIO

    -3.0200

    98.2

    -3.08%

  • NGG

    0.5200

    81.2

    +0.64%

  • RELX

    0.1200

    34.67

    +0.35%

  • VOD

    0.1300

    16.22

    +0.8%

  • BTI

    1.5100

    57.35

    +2.63%

  • AZN

    -1.2600

    157.24

    -0.8%

  • BP

    -0.1000

    42.83

    -0.23%

AI 'agent' fever comes with lurking security threats
AI 'agent' fever comes with lurking security threats / Photo: © AFP/File

AI 'agent' fever comes with lurking security threats

Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge.

Text size:

Powered by a wave of hype, OpenClaw today claims more than three million users worldwide.

The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks.

"We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company.

In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behaviour of six AI agents created with OpenClaw.

They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information.

Many users have posted similar stories of OpenClaw mishaps online.

"When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency.

And the security gaps are not limited to the agents' own mistaken actions.

To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers.

- 'Delete your database' -

AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks.

"As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being used and using that then to interrogate the systems for more information."

Palo Alto's Unit 42 research division said in early March that it had found traces of attempted attacks in the form of hidden instructions for agents added to websites.

One such command ordered any agent who might read it to "delete your database".

Other cybersecurity firms and researchers have warned that attackers could gain access to agents via so-called skills -- downloadable files that users can add to their systems to give them new abilities.

Among such files freely available for download, some include hidden instructions for malicious actions like exfiltrating data.

OpenClaw creator Peter Steinberger says he is well aware of the risks.

"I purposefully didn't make it simpler so people would stop and read and understand: what is AI, that AI can make mistakes, what is prompt injection -- some basics that you really should understand when you use that technology," he told AFP in March.

Whitmore argued that expecting users to create their own guardrails for agents is "pretty unrealistic".

"People are going to adopt innovation and really see what it's capable of before they ask the questions about, 'how do I secure my own data?'," she predicted.

"That's going to cause some significant challenges in terms of data breaches in 2026."

A.Zhang--ThChM