Berliner Boersenzeitung - AI agents open door to new hacking threats

EUR -
AED 4.231433
AFN 74.892934
ALL 93.964547
AMD 422.42859
AOA 1057.71362
ARS 1715.616549
AUD 1.639899
AWG 2.075388
AZN 1.95509
BAM 1.964441
BBD 2.320889
BDT 142.295919
BHD 0.434489
BIF 3453.699027
BMD 1.152193
BND 1.48453
BOB 13.569099
BRL 5.851763
BSD 1.152359
BTN 110.199606
BWP 15.746469
BYN 3.372033
BYR 22582.986129
BZD 2.317695
CAD 1.614655
CDF 2621.239218
CHF 0.928846
CLF 0.027096
CLP 1066.41274
CNY 7.783353
CNH 7.775587
COP 3599.082761
CRC 523.89994
CUC 1.152193
CUP 30.533119
CVE 111.359268
CZK 24.204641
DJF 204.767487
DKK 7.47521
DOP 67.08644
DZD 152.919167
EGP 58.84239
ERN 17.282898
ETB 186.000011
FJD 2.553149
FKP 0.867174
GBP 0.856051
GEL 3.018565
GGP 0.867174
GHS 13.474877
GIP 0.867174
GMD 85.262595
GNF 10101.857255
GTQ 8.792676
GYD 241.096794
HKD 9.036708
HNL 30.87481
HRK 7.53315
HTG 150.672767
HUF 362.580193
IDR 20794.263843
ILS 3.531443
IMP 0.867174
INR 110.247661
IQD 1509.540037
IRR 1584265.60873
ISK 142.606705
JEP 0.867174
JMD 182.251673
JOD 0.816868
JPY 184.750148
KES 149.070356
KGS 100.758911
KHR 4654.860526
KMF 496.020675
KRW 1644.974733
KWD 0.356892
KYD 0.960337
KZT 546.678406
LAK 26131.741487
LBP 103178.89777
LKR 387.072622
LRD 209.134754
LSL 19.137841
LTL 3.402127
LVL 0.69695
LYD 7.379782
MAD 10.812757
MDL 20.29353
MGA 4926.821346
MKD 61.505418
MMK 2419.425088
MNT 4143.544445
MOP 9.310877
MRU 46.214335
MUR 54.394729
MVR 17.813507
MWK 2000.207131
MXN 19.983063
MYR 4.693692
MZN 73.636643
NAD 19.137958
NGN 1572.121116
NIO 42.407828
NOK 10.978792
NPR 176.313021
NZD 1.961834
OMR 0.443021
PAB 1.152404
PEN 3.904876
PGK 5.084365
PHP 70.89455
PKR 320.191151
PLN 4.307491
PYG 6887.295252
QAR 4.198819
RON 5.246048
RSD 117.399306
RUB 91.859024
RWF 1690.26738
SAR 4.2996
SBD 9.299986
SCR 15.599018
SDG 691.315584
SEK 10.991174
SGD 1.477694
SLE 28.464345
SOS 658.591239
SRD 43.489504
STD 23848.072347
STN 24.60803
SVC 10.083354
SZL 19.113073
THB 38.487877
TJS 10.641818
TMT 4.044198
TND 3.407187
TRY 54.735624
TTD 7.821643
TWD 37.342774
TZS 3050.429113
UAH 51.410942
UGX 4315.984789
USD 1.152193
UYU 46.353898
UZS 13833.851174
VES 856.420682
VND 30281.364793
VUV 137.723124
WST 3.171439
XAF 658.878091
XAG 0.019493
XAU 0.000281
XCD 3.113859
XCG 2.076899
XDR 0.820359
XOF 658.855116
XPF 119.331742
YER 274.596437
ZAR 19.01568
ZMK 10371.122817
ZMW 21.520315
ZWL 371.005731
  • RBGPF

    3.2100

    69.21

    +4.64%

  • CMSC

    0.1200

    21.81

    +0.55%

  • CMSD

    -0.0200

    22.02

    -0.09%

  • GSK

    -1.1500

    52.07

    -2.21%

  • BCE

    -0.6300

    21.7

    -2.9%

  • NGG

    1.5100

    80.39

    +1.88%

  • BCC

    -2.3000

    75.38

    -3.05%

  • RIO

    3.5200

    97.18

    +3.62%

  • JRI

    0.1100

    12.87

    +0.85%

  • AZN

    -1.9600

    171.34

    -1.14%

  • BTI

    -1.3800

    61.69

    -2.24%

  • RELX

    -1.6200

    36.61

    -4.43%

  • RYCEF

    1.1600

    19.63

    +5.91%

  • VOD

    0.0100

    16.14

    +0.06%

  • BP

    0.9000

    44.22

    +2.04%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

(U.Gruber--BBZ)