The China Mail - AI agents open door to new hacking threats

USD -
AED 3.67315
AFN 63.503991
ALL 83.375041
AMD 377.180403
ANG 1.790083
AOA 917.000367
ARS 1383.990604
AUD 1.452433
AWG 1.8
AZN 1.70397
BAM 1.69972
BBD 2.014322
BDT 122.712716
BGN 1.709309
BHD 0.377349
BIF 2968.5
BMD 1
BND 1.28787
BOB 6.936019
BRL 5.255304
BSD 1.000117
BTN 94.794201
BWP 13.787919
BYN 2.976987
BYR 19600
BZD 2.011341
CAD 1.38995
CDF 2282.50392
CHF 0.798523
CLF 0.023433
CLP 925.260396
CNY 6.91185
CNH 6.92017
COP 3680.29
CRC 464.427092
CUC 1
CUP 26.5
CVE 96.12504
CZK 21.309304
DJF 177.720393
DKK 6.492704
DOP 59.72504
DZD 133.275765
EGP 52.642155
ERN 15
ETB 156.62504
EUR 0.866104
FJD 2.260391
FKP 0.75231
GBP 0.75375
GEL 2.680391
GGP 0.75231
GHS 10.97039
GIP 0.75231
GMD 73.503851
GNF 8780.000355
GTQ 7.653901
GYD 209.354875
HKD 7.82605
HNL 26.510388
HRK 6.545204
HTG 131.099243
HUF 338.020388
IDR 16990.8
ILS 3.13762
IMP 0.75231
INR 94.864204
IQD 1310
IRR 1313250.000352
ISK 124.760386
JEP 0.75231
JMD 157.422697
JOD 0.70904
JPY 160.29904
KES 129.903801
KGS 87.450384
KHR 4012.00035
KMF 428.00035
KPW 899.886996
KRW 1508.00035
KWD 0.30791
KYD 0.833446
KZT 483.490125
LAK 21900.000349
LBP 89550.000349
LKR 315.037957
LRD 183.625039
LSL 17.160381
LTL 2.95274
LVL 0.60489
LYD 6.375039
MAD 9.344504
MDL 17.566669
MGA 4175.000347
MKD 53.384435
MMK 2102.490525
MNT 3571.507434
MOP 8.069509
MRU 40.120379
MUR 46.770378
MVR 15.450378
MWK 1737.000345
MXN 18.121104
MYR 3.924039
MZN 63.950377
NAD 17.160377
NGN 1383.460377
NIO 36.720377
NOK 9.70286
NPR 151.667079
NZD 1.740645
OMR 0.385081
PAB 1.000109
PEN 3.459504
PGK 4.309039
PHP 60.550375
PKR 279.203701
PLN 3.72275
PYG 6538.855961
QAR 3.65325
RON 4.427304
RSD 101.818038
RUB 81.419514
RWF 1461
SAR 3.752351
SBD 8.042037
SCR 14.429246
SDG 601.000339
SEK 9.47367
SGD 1.292804
SHP 0.750259
SLE 24.550371
SLL 20969.510825
SOS 571.503662
SRD 37.601038
STD 20697.981008
STN 21.35
SVC 8.75063
SYP 111.824334
SZL 17.160369
THB 32.860369
TJS 9.556069
TMT 3.5
TND 2.926038
TOP 2.40776
TRY 44.433404
TTD 6.795201
TWD 32.044404
TZS 2576.487038
UAH 43.837189
UGX 3725.687866
UYU 40.481115
UZS 12205.000334
VES 467.928355
VND 26337.5
VUV 119.756335
WST 2.77551
XAF 570.070221
XAG 0.014291
XAU 0.000222
XCD 2.70255
XCG 1.802452
XDR 0.706792
XOF 568.000332
XPF 104.103591
YER 238.603589
ZAR 17.119995
ZMK 9001.203584
ZMW 18.826586
ZWL 321.999592
  • RBGPF

    -13.5000

    69

    -19.57%

  • CMSD

    -0.0900

    22.66

    -0.4%

  • GSK

    -0.1000

    53.84

    -0.19%

  • RIO

    0.8500

    86.64

    +0.98%

  • VOD

    -0.1400

    14.49

    -0.97%

  • NGG

    -0.4800

    81.92

    -0.59%

  • BCE

    -0.2200

    25.25

    -0.87%

  • CMSC

    -0.0500

    22.77

    -0.22%

  • RYCEF

    -0.5900

    14.65

    -4.03%

  • RELX

    -0.1000

    31.97

    -0.31%

  • AZN

    5.0200

    188.42

    +2.66%

  • JRI

    -0.2700

    11.8

    -2.29%

  • BCC

    0.1400

    74.43

    +0.19%

  • BTI

    0.3749

    57.8

    +0.65%

  • BP

    0.5100

    46.68

    +1.09%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: © AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Zhang--ThChM