The China Mail - AI agents open door to new hacking threats

USD -
AED 3.672497
AFN 65.500282
ALL 80.118822
AMD 365.101228
ANG 1.789783
AOA 917.999952
ARS 1473.822201
AUD 1.40989
AWG 1.80125
AZN 1.677673
BAM 1.689027
BBD 2.009905
BDT 122.501501
BGN 1.696366
BHD 0.376353
BIF 2983.311384
BMD 1
BND 1.276452
BOB 11.630749
BRL 5.218395
BSD 0.997902
BTN 95.172426
BWP 13.444507
BYN 3.035115
BYR 19600
BZD 2.007055
CAD 1.38684
CDF 2273.000285
CHF 0.811885
CLF 0.023213
CLP 913.597632
CNY 6.743198
CNH 6.742026
COP 3131.8
CRC 448.981178
CUC 1
CUP 26.5
CVE 95.223908
CZK 20.918973
DJF 177.708307
DKK 6.455725
DOP 58.413323
DZD 131.548585
EGP 49.808802
ERN 15
ETB 161.425894
EUR 0.863597
FJD 2.2342
FKP 0.739036
GBP 0.738065
GEL 2.610503
GGP 0.739036
GHS 10.927886
GIP 0.739036
GMD 73.502352
GNF 8766.165073
GTQ 7.61376
GYD 208.747317
HKD 7.846631
HNL 26.751064
HRK 6.506601
HTG 130.529588
HUF 313.659503
IDR 17799.55
ILS 2.955105
IMP 0.739036
INR 95.60255
IQD 1307.282109
IRR 1374587.49143
ISK 122.795489
JEP 0.739036
JMD 158.0345
JOD 0.709018
JPY 159.073009
KES 129.290338
KGS 87.450231
KHR 4038.118596
KMF 426.999733
KPW 900.000294
KRW 1415.439659
KWD 0.308679
KYD 0.831624
KZT 463.058356
LAK 22523.133255
LBP 89358.962735
LKR 332.07394
LRD 181.117151
LSL 16.144443
LTL 2.95274
LVL 0.60489
LYD 6.354251
MAD 9.255973
MDL 17.3033
MGA 4296.404406
MKD 53.12925
MMK 2099.791609
MNT 3596.010349
MOP 8.065977
MRU 40.077551
MUR 47.110234
MVR 15.450075
MWK 1730.479427
MXN 17.011241
MYR 4.079597
MZN 63.910141
NAD 16.144304
NGN 1358.37955
NIO 36.728702
NOK 9.432505
NPR 152.279341
NZD 1.693435
OMR 0.384498
PAB 0.997958
PEN 3.365905
PGK 4.482884
PHP 61.591011
PKR 277.181559
PLN 3.71955
PYG 5989.818345
QAR 3.637965
RON 4.527602
RSD 101.332942
RUB 83.92164
RWF 1467.47555
SAR 3.746487
SBD 8.048583
SCR 13.870251
SDG 600.500592
SEK 9.512315
SGD 1.27795
SHP 0.740866
SLE 24.498611
SLL 20969.499227
SOS 570.305922
SRD 37.974503
STD 20697.981008
STN 21.157898
SVC 8.731622
SYP 13001.999906
SZL 16.14239
THB 33.084502
TJS 9.215989
TMT 3.51
TND 2.925732
TOP 2.40776
TRY 47.899701
TTD 6.760999
TWD 31.900897
TZS 2649.949627
UAH 44.643485
UGX 3707.397956
UYU 39.984283
UZS 11880.324535
VES 770.109102
VND 26076.5
VUV 117.940389
WST 2.73449
XAF 566.469052
XAG 0.015267
XAU 0.000228
XCD 2.70255
XCG 1.798484
XDR 0.707052
XOF 566.473944
XPF 102.991023
YER 237.196067
ZAR 16.18029
ZMK 9001.180041
ZMW 18.860674
ZWL 321.999592
  • CMSC

    -0.0250

    21.45

    -0.12%

  • CMSD

    -0.0100

    21.58

    -0.05%

  • GSK

    -0.4785

    49.52

    -0.97%

  • NGG

    -0.1500

    81.05

    -0.19%

  • RYCEF

    0.1300

    20.84

    +0.62%

  • AZN

    -0.7900

    156.45

    -0.5%

  • RIO

    -0.4100

    95.68

    -0.43%

  • VOD

    0.2000

    16.42

    +1.22%

  • BCE

    0.1500

    23.47

    +0.64%

  • RELX

    -0.2400

    34.43

    -0.7%

  • RBGPF

    0.0000

    71.34

    0%

  • BCC

    -0.8900

    83.24

    -1.07%

  • JRI

    0.0635

    12.61

    +0.5%

  • BTI

    -0.2900

    57.06

    -0.51%

  • BP

    0.2196

    42.53

    +0.52%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: © AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Zhang--ThChM