The Fort Worth Press - AI agents open door to new hacking threats

USD -
AED 3.672498
AFN 66.374624
ALL 82.891062
AMD 382.105484
ANG 1.790055
AOA 917.000265
ARS 1446.111798
AUD 1.509457
AWG 1.80125
AZN 1.69945
BAM 1.678236
BBD 2.018646
BDT 122.628476
BGN 1.678398
BHD 0.376991
BIF 2961.256275
BMD 1
BND 1.297979
BOB 6.925579
BRL 5.31099
BSD 1.002244
BTN 90.032049
BWP 13.315657
BYN 2.90153
BYR 19600
BZD 2.015729
CAD 1.394565
CDF 2229.999854
CHF 0.803415
CLF 0.023394
CLP 917.729983
CNY 7.07165
CNH 7.067635
COP 3796.99
CRC 491.421364
CUC 1
CUP 26.5
CVE 94.616395
CZK 20.762402
DJF 178.481789
DKK 6.410465
DOP 63.686561
DZD 130.081006
EGP 47.5783
ERN 15
ETB 156.280403
EUR 0.85828
FJD 2.261962
FKP 0.750125
GBP 0.749325
GEL 2.702059
GGP 0.750125
GHS 11.416779
GIP 0.750125
GMD 73.000012
GNF 8709.00892
GTQ 7.677291
GYD 209.68946
HKD 7.78435
HNL 26.389336
HRK 6.462502
HTG 131.282447
HUF 327.919498
IDR 16652
ILS 3.231155
IMP 0.750125
INR 90.007498
IQD 1312.956662
IRR 42124.999891
ISK 127.879701
JEP 0.750125
JMD 160.623651
JOD 0.709011
JPY 154.910502
KES 129.349486
KGS 87.449585
KHR 4014.227424
KMF 421.999977
KPW 899.992858
KRW 1471.139743
KWD 0.30686
KYD 0.83526
KZT 506.587952
LAK 21742.171042
LBP 89752.828464
LKR 309.374155
LRD 176.902912
LSL 17.013777
LTL 2.95274
LVL 0.60489
LYD 5.447985
MAD 9.247548
MDL 17.048443
MGA 4457.716053
MKD 52.892165
MMK 2099.902882
MNT 3550.784265
MOP 8.035628
MRU 39.710999
MUR 46.070097
MVR 15.409729
MWK 1737.95151
MXN 18.21685
MYR 4.1095
MZN 63.902189
NAD 17.013777
NGN 1450.250119
NIO 36.881624
NOK 10.105016
NPR 144.049872
NZD 1.732875
OMR 0.3845
PAB 1.002325
PEN 3.37046
PGK 4.251065
PHP 58.994993
PKR 283.139992
PLN 3.62913
PYG 6950.492756
QAR 3.663323
RON 4.369801
RSD 100.749025
RUB 75.955865
RWF 1458.303837
SAR 3.752867
SBD 8.223823
SCR 13.590725
SDG 601.501691
SEK 9.412745
SGD 1.295395
SHP 0.750259
SLE 22.999848
SLL 20969.498139
SOS 571.823287
SRD 38.643498
STD 20697.981008
STN 21.023817
SVC 8.769634
SYP 11056.894377
SZL 17.008825
THB 31.864504
TJS 9.210862
TMT 3.5
TND 2.941946
TOP 2.40776
TRY 42.528197
TTD 6.795179
TWD 31.256047
TZS 2439.99956
UAH 42.259148
UGX 3553.316915
UYU 39.265994
UZS 11939.350775
VES 248.585901
VND 26362.5
VUV 122.113889
WST 2.800321
XAF 562.862377
XAG 0.017228
XAU 0.000237
XCD 2.70255
XCG 1.806356
XDR 0.70002
XOF 562.867207
XPF 102.334841
YER 238.399242
ZAR 16.93296
ZMK 9001.196253
ZMW 23.026725
ZWL 321.999592
  • RBGPF

    0.0000

    78.35

    0%

  • CMSC

    0.0400

    23.48

    +0.17%

  • CMSD

    -0.0300

    23.32

    -0.13%

  • RIO

    -0.5500

    73.73

    -0.75%

  • NGG

    -0.5800

    75.91

    -0.76%

  • SCS

    -0.1200

    16.23

    -0.74%

  • GSK

    -0.4000

    48.57

    -0.82%

  • BTI

    0.5300

    58.04

    +0.91%

  • AZN

    -0.8200

    90.03

    -0.91%

  • BP

    -0.0100

    37.23

    -0.03%

  • RYCEF

    0.4600

    14.67

    +3.14%

  • RELX

    0.3500

    40.54

    +0.86%

  • BCC

    -2.3000

    74.26

    -3.1%

  • JRI

    0.0500

    13.75

    +0.36%

  • VOD

    0.0500

    12.64

    +0.4%

  • BCE

    0.0400

    23.22

    +0.17%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: © AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

J.Barnes--TFWP