Berliner Boersenzeitung - AI agents open door to new hacking threats

EUR -
AED 4.30721
AFN 75.04906
ALL 95.511578
AMD 434.790006
ANG 2.098881
AOA 1076.479183
ARS 1633.590788
AUD 1.627507
AWG 2.110743
AZN 1.998135
BAM 1.957945
BBD 2.36232
BDT 143.911791
BGN 1.956074
BHD 0.442846
BIF 3489.761182
BMD 1.172635
BND 1.49616
BOB 8.104467
BRL 5.844769
BSD 1.1729
BTN 111.261714
BWP 15.93962
BYN 3.309795
BYR 22983.642195
BZD 2.358906
CAD 1.593769
CDF 2720.513174
CHF 0.915939
CLF 0.026785
CLP 1054.199114
CNY 8.007044
CNH 8.01045
COP 4288.794539
CRC 533.238815
CUC 1.172635
CUP 31.074822
CVE 110.755819
CZK 24.37678
DJF 208.401119
DKK 7.472268
DOP 69.776325
DZD 155.421478
EGP 62.903067
ERN 17.589522
ETB 184.104084
FJD 2.616195
FKP 0.863507
GBP 0.863135
GEL 3.148572
GGP 0.863507
GHS 13.138031
GIP 0.863507
GMD 85.602758
GNF 10289.870838
GTQ 8.960697
GYD 245.376635
HKD 9.18804
HNL 31.215994
HRK 7.530314
HTG 153.644064
HUF 362.609217
IDR 20303.937137
ILS 3.452038
IMP 0.863507
INR 111.228692
IQD 1536.151596
IRR 1540842.135344
ISK 143.812385
JEP 0.863507
JMD 183.781361
JOD 0.831444
JPY 184.148271
KES 151.446236
KGS 102.512326
KHR 4705.20161
KMF 492.507029
KPW 1055.372308
KRW 1726.963181
KWD 0.360175
KYD 0.977442
KZT 543.267779
LAK 25774.513442
LBP 105009.447276
LKR 374.857478
LRD 215.589357
LSL 19.536543
LTL 3.462486
LVL 0.709316
LYD 7.45214
MAD 10.828156
MDL 20.208607
MGA 4872.298025
MKD 61.58302
MMK 2462.531881
MNT 4198.466183
MOP 9.464155
MRU 46.89411
MUR 55.161185
MVR 18.123116
MWK 2042.147896
MXN 20.473739
MYR 4.654233
MZN 74.935737
NAD 19.536538
NGN 1612.494489
NIO 43.059592
NOK 10.876123
NPR 178.010182
NZD 1.986965
OMR 0.450756
PAB 1.17287
PEN 4.113256
PGK 5.089675
PHP 71.920083
PKR 326.872391
PLN 4.246116
PYG 7213.611083
QAR 4.272789
RON 5.203454
RSD 117.281962
RUB 87.925585
RWF 1714.392086
SAR 4.397591
SBD 9.438049
SCR 17.149829
SDG 704.171511
SEK 10.814215
SGD 1.492858
SHP 0.87549
SLE 28.876177
SLL 24589.561066
SOS 670.165086
SRD 43.924599
STD 24271.172941
STN 24.859858
SVC 10.263252
SYP 129.60945
SZL 19.536529
THB 38.125294
TJS 11.001451
TMT 4.110085
TND 3.379578
TOP 2.823423
TRY 52.968153
TTD 7.96147
TWD 37.088138
TZS 3054.714062
UAH 51.536521
UGX 4410.264652
USD 1.172635
UYU 46.775838
UZS 13998.332237
VES 573.351287
VND 30905.962944
VUV 139.316425
WST 3.208318
XAF 656.724148
XAG 0.015459
XAU 0.000254
XCD 3.169105
XCG 2.11385
XDR 0.81498
XOF 657.266022
XPF 119.331742
YER 279.849722
ZAR 19.527126
ZMK 10555.124618
ZMW 21.903587
ZWL 377.587929
  • RBGPF

    -1.1500

    62.6

    -1.84%

  • BCC

    -1.1200

    78.15

    -1.43%

  • RYCEF

    0.5000

    16.3

    +3.07%

  • RELX

    -0.2350

    36.355

    -0.65%

  • NGG

    -1.0500

    88.49

    -1.19%

  • JRI

    -0.0100

    12.98

    -0.08%

  • RIO

    0.1300

    100.61

    +0.13%

  • BCE

    0.1750

    23.955

    +0.73%

  • CMSD

    0.1500

    23.28

    +0.64%

  • GSK

    -0.6890

    51.621

    -1.33%

  • VOD

    0.3500

    16.15

    +2.17%

  • AZN

    -2.4600

    184.91

    -1.33%

  • BP

    -0.9750

    46.405

    -2.1%

  • BTI

    -0.0950

    58.705

    -0.16%

  • CMSC

    0.0500

    22.87

    +0.22%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

(U.Gruber--BBZ)