The China Mail - AI agents open door to new hacking threats

USD -
AED 3.672501
AFN 62.999886
ALL 81.2693
AMD 368.114362
ANG 1.790076
AOA 917.999926
ARS 1385.000064
AUD 1.381072
AWG 1.8025
AZN 1.720749
BAM 1.666077
BBD 2.014457
BDT 122.941149
BGN 1.671156
BHD 0.377471
BIF 2977.296929
BMD 1
BND 1.273246
BOB 6.911416
BRL 4.894303
BSD 1.000217
BTN 95.599836
BWP 13.500701
BYN 2.796427
BYR 19600
BZD 2.01156
CAD 1.37024
CDF 2224.999845
CHF 0.782115
CLF 0.023209
CLP 913.460076
CNY 6.792097
CNH 6.788855
COP 3788.37
CRC 456.440902
CUC 1
CUP 26.5
CVE 93.93689
CZK 20.809097
DJF 178.103956
DKK 6.384535
DOP 59.027231
DZD 132.370621
EGP 52.999201
ERN 15
ETB 156.17715
EUR 0.85455
FJD 2.187298
FKP 0.732576
GBP 0.73945
GEL 2.670051
GGP 0.732576
GHS 11.291855
GIP 0.732576
GMD 73.516689
GNF 8776.211713
GTQ 7.631494
GYD 209.250717
HKD 7.83065
HNL 26.597149
HRK 6.438806
HTG 130.672573
HUF 307.065023
IDR 17482
ILS 2.903155
IMP 0.732576
INR 95.72135
IQD 1310.162706
IRR 1311999.999969
ISK 122.710238
JEP 0.732576
JMD 158.040677
JOD 0.709029
JPY 157.8385
KES 129.149763
KGS 87.450274
KHR 4012.437705
KMF 420.000118
KPW 900.018246
KRW 1490.85959
KWD 0.30834
KYD 0.833461
KZT 463.898117
LAK 21925.486738
LBP 89566.76932
LKR 323.055495
LRD 183.03638
LSL 16.532284
LTL 2.95274
LVL 0.60489
LYD 6.327815
MAD 9.128129
MDL 17.117957
MGA 4179.356229
MKD 52.646412
MMK 2098.953745
MNT 3580.85029
MOP 8.064861
MRU 39.897262
MUR 46.810352
MVR 15.397294
MWK 1734.441354
MXN 17.237498
MYR 3.930263
MZN 63.91038
NAD 16.532073
NGN 1370.519894
NIO 36.810495
NOK 9.183085
NPR 152.953704
NZD 1.686326
OMR 0.384518
PAB 1.000175
PEN 3.427819
PGK 4.355862
PHP 61.399865
PKR 278.627173
PLN 3.63465
PYG 6105.472094
QAR 3.645959
RON 4.447698
RSD 100.298973
RUB 73.451572
RWF 1462.859869
SAR 3.754672
SBD 8.029009
SCR 13.956052
SDG 600.497735
SEK 9.31555
SGD 1.27258
SHP 0.746601
SLE 24.624983
SLL 20969.500038
SOS 571.611117
SRD 37.254498
STD 20697.981008
STN 20.871402
SVC 8.751171
SYP 110.529423
SZL 16.526884
THB 32.376031
TJS 9.351751
TMT 3.5
TND 2.908879
TOP 2.40776
TRY 45.417905
TTD 6.787631
TWD 31.541021
TZS 2601.398013
UAH 43.959484
UGX 3759.408104
UYU 39.772219
UZS 12133.112416
VES 504.28356
VND 26350.5
VUV 118.32345
WST 2.709295
XAF 558.801055
XAG 0.011571
XAU 0.000213
XCD 2.70255
XCG 1.802539
XDR 0.694969
XOF 558.801055
XPF 101.593413
YER 238.650147
ZAR 16.46445
ZMK 9001.189445
ZMW 18.8284
ZWL 321.999592
  • RBGPF

    0.0000

    61

    0%

  • CMSC

    -0.0100

    23.11

    -0.04%

  • CMSD

    -0.0100

    23.6

    -0.04%

  • BCC

    -1.2700

    67.93

    -1.87%

  • BCE

    0.1900

    24.47

    +0.78%

  • NGG

    0.0800

    87.24

    +0.09%

  • RYCEF

    -0.3900

    16.2

    -2.41%

  • GSK

    1.0900

    50.9

    +2.14%

  • AZN

    2.6800

    184.54

    +1.45%

  • RIO

    1.6000

    109.5

    +1.46%

  • RELX

    -0.5000

    32.77

    -1.53%

  • BP

    0.1800

    44.4

    +0.41%

  • BTI

    3.2000

    63.64

    +5.03%

  • JRI

    0.0100

    13.14

    +0.08%

  • VOD

    -1.2250

    15.095

    -8.12%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: © AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Zhang--ThChM