The China Mail - AI agents open door to new hacking threats

USD -
AED 3.672503
AFN 66.40135
ALL 83.577028
AMD 382.730415
ANG 1.789982
AOA 916.99937
ARS 1419.988799
AUD 1.530421
AWG 1.8075
AZN 1.726725
BAM 1.692008
BBD 2.014958
BDT 122.146716
BGN 1.69191
BHD 0.377032
BIF 2946.886653
BMD 1
BND 1.303554
BOB 6.938286
BRL 5.291202
BSD 1.000502
BTN 88.679433
BWP 13.388763
BYN 3.410355
BYR 19600
BZD 2.012017
CAD 1.402295
CDF 2147.999849
CHF 0.805055
CLF 0.023909
CLP 937.9395
CNY 7.11965
CNH 7.121415
COP 3753.72
CRC 502.320833
CUC 1
CUP 26.5
CVE 95.624995
CZK 21.0116
DJF 178.159229
DKK 6.45983
DOP 64.249724
DZD 130.504961
EGP 47.259948
ERN 15
ETB 153.632223
EUR 0.865203
FJD 2.278987
FKP 0.760102
GBP 0.759075
GEL 2.705032
GGP 0.760102
GHS 10.944671
GIP 0.760102
GMD 73.000141
GNF 8684.668161
GTQ 7.66845
GYD 209.299207
HKD 7.773945
HNL 26.322961
HRK 6.519401
HTG 130.986988
HUF 331.919547
IDR 16697
ILS 3.23525
IMP 0.760102
INR 88.70745
IQD 1310.523812
IRR 42099.999792
ISK 126.480273
JEP 0.760102
JMD 161.038579
JOD 0.709009
JPY 154.139018
KES 129.213757
KGS 87.45037
KHR 4015.000267
KMF 420.999761
KPW 900.001961
KRW 1456.179725
KWD 0.30709
KYD 0.833687
KZT 524.097063
LAK 21722.392837
LBP 89583.978546
LKR 304.200009
LRD 183.077329
LSL 17.192699
LTL 2.95274
LVL 0.60489
LYD 5.459328
MAD 9.261661
MDL 16.981703
MGA 4494.683382
MKD 53.222318
MMK 2099.688142
MNT 3580.599313
MOP 8.009828
MRU 39.728682
MUR 45.860477
MVR 15.404997
MWK 1734.887222
MXN 18.379596
MYR 4.163022
MZN 63.959822
NAD 17.192699
NGN 1436.610157
NIO 36.813372
NOK 10.130996
NPR 141.895686
NZD 1.771746
OMR 0.384498
PAB 1.000428
PEN 3.376575
PGK 4.223805
PHP 58.970405
PKR 282.888599
PLN 3.66405
PYG 7087.087607
QAR 3.64632
RON 4.399041
RSD 101.391977
RUB 81.250681
RWF 1454.218254
SAR 3.750503
SBD 8.230592
SCR 13.741165
SDG 600.494403
SEK 9.513475
SGD 1.302425
SHP 0.750259
SLE 23.236536
SLL 20969.499529
SOS 570.768552
SRD 38.496504
STD 20697.981008
STN 21.196889
SVC 8.752974
SYP 11056.839565
SZL 17.189528
THB 32.349855
TJS 9.26848
TMT 3.51
TND 2.953357
TOP 2.342104
TRY 42.238603
TTD 6.785761
TWD 30.9811
TZS 2455.599549
UAH 42.069631
UGX 3511.534252
UYU 39.804309
UZS 12020.018946
VES 228.194043
VND 26300
VUV 122.518583
WST 2.820889
XAF 567.53013
XAG 0.019786
XAU 0.000243
XCD 2.70255
XCG 1.802933
XDR 0.705825
XOF 567.52522
XPF 103.174569
YER 238.530785
ZAR 17.144055
ZMK 9001.208506
ZMW 22.634213
ZWL 321.999592
  • RBGPF

    0.0000

    76

    0%

  • RYCEF

    0.0200

    14.82

    +0.13%

  • VOD

    0.1200

    11.7

    +1.03%

  • RELX

    -0.2400

    42.03

    -0.57%

  • CMSD

    0.0600

    24.16

    +0.25%

  • CMSC

    0.0400

    23.89

    +0.17%

  • NGG

    -0.4200

    77.33

    -0.54%

  • SCS

    -0.0200

    15.74

    -0.13%

  • BTI

    0.8300

    55.42

    +1.5%

  • BP

    0.5400

    37.12

    +1.45%

  • GSK

    0.7300

    47.36

    +1.54%

  • RIO

    0.9600

    70.29

    +1.37%

  • BCC

    -0.8100

    69.83

    -1.16%

  • JRI

    -0.0600

    13.68

    -0.44%

  • BCE

    -0.2500

    22.94

    -1.09%

  • AZN

    2.9000

    87.48

    +3.32%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: © AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Zhang--ThChM