The Fort Worth Press - AI agents open door to new hacking threats

USD -
AED 3.672494
AFN 64.000493
ALL 81.450493
AMD 370.780251
ANG 1.789884
AOA 917.999881
ARS 1392.559404
AUD 1.38748
AWG 1.8
AZN 1.695216
BAM 1.669697
BBD 2.01454
BDT 122.725158
BGN 1.668102
BHD 0.37765
BIF 2976
BMD 1
BND 1.275896
BOB 6.911331
BRL 4.954702
BSD 1.000226
BTN 94.881811
BWP 13.592996
BYN 2.822528
BYR 19600
BZD 2.011629
CAD 1.35921
CDF 2319.999847
CHF 0.780701
CLF 0.022861
CLP 899.749905
CNY 6.82825
CNH 6.816975
COP 3657.25
CRC 454.73562
CUC 1
CUP 26.5
CVE 94.449942
CZK 20.76365
DJF 177.719703
DKK 6.36849
DOP 59.49346
DZD 132.464709
EGP 53.495099
ERN 15
ETB 156.999734
EUR 0.85227
FJD 2.190603
FKP 0.736618
GBP 0.735645
GEL 2.679571
GGP 0.736618
GHS 11.202571
GIP 0.736618
GMD 72.99985
GNF 8774.999794
GTQ 7.641507
GYD 209.25239
HKD 7.833965
HNL 26.619786
HRK 6.4231
HTG 131.024649
HUF 308.5225
IDR 17376
ILS 2.94745
IMP 0.736618
INR 94.92485
IQD 1310
IRR 1313999.999982
ISK 122.559434
JEP 0.736618
JMD 156.725146
JOD 0.708968
JPY 156.774502
KES 129.095472
KGS 87.420496
KHR 4012.502072
KMF 420.000157
KPW 899.999976
KRW 1468.440084
KWD 0.307899
KYD 0.833543
KZT 463.288124
LAK 21979.999983
LBP 89550.000285
LKR 319.671116
LRD 183.875001
LSL 16.659854
LTL 2.95274
LVL 0.604891
LYD 6.349683
MAD 9.251249
MDL 17.233504
MGA 4150.000427
MKD 52.539606
MMK 2099.490131
MNT 3577.850535
MOP 8.070846
MRU 39.969687
MUR 46.76048
MVR 15.455009
MWK 1741.552774
MXN 17.429855
MYR 3.952497
MZN 63.895715
NAD 16.660055
NGN 1375.980277
NIO 36.71013
NOK 9.27605
NPR 151.803598
NZD 1.689805
OMR 0.384489
PAB 1.000201
PEN 3.507503
PGK 4.33875
PHP 61.469602
PKR 278.77498
PLN 3.61942
PYG 6151.626275
QAR 3.643499
RON 4.429904
RSD 99.996991
RUB 75.001641
RWF 1461.5
SAR 3.74998
SBD 8.04211
SCR 14.88162
SDG 600.499176
SEK 9.213799
SGD 1.27268
SHP 0.746601
SLE 24.599275
SLL 20969.496166
SOS 571.000167
SRD 37.457968
STD 20697.981008
STN 21.21
SVC 8.7523
SYP 110.524981
SZL 16.659994
THB 32.417043
TJS 9.381822
TMT 3.505
TND 2.88175
TOP 2.40776
TRY 45.19573
TTD 6.789386
TWD 31.590949
TZS 2610.000207
UAH 43.949336
UGX 3760.987334
UYU 39.889518
UZS 11949.999996
VES 488.942755
VND 26338.5
VUV 117.651389
WST 2.715189
XAF 560.041494
XAG 0.013321
XAU 0.000218
XCD 2.70255
XCG 1.80265
XDR 0.69563
XOF 559.99986
XPF 102.15034
YER 238.600947
ZAR 16.58375
ZMK 9001.195339
ZMW 18.67895
ZWL 321.999592
  • GSK

    -0.7000

    51.61

    -1.36%

  • CMSD

    0.1500

    23.28

    +0.64%

  • BCC

    -1.1400

    78.13

    -1.46%

  • BCE

    0.1800

    23.96

    +0.75%

  • RIO

    0.1000

    100.58

    +0.1%

  • JRI

    -0.0100

    12.98

    -0.08%

  • BP

    -0.9700

    46.41

    -2.09%

  • CMSC

    0.0600

    22.88

    +0.26%

  • BTI

    -0.0900

    58.71

    -0.15%

  • NGG

    -1.0600

    88.48

    -1.2%

  • RBGPF

    0.5000

    63.1

    +0.79%

  • AZN

    -2.6300

    184.74

    -1.42%

  • RELX

    -0.2400

    36.35

    -0.66%

  • RYCEF

    0.5500

    16.35

    +3.36%

  • VOD

    0.3500

    16.15

    +2.17%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: © AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

J.Barnes--TFWP