The Prague Post - AI agents open door to new hacking threats

EUR -
AED 4.183608
AFN 75.185325
ALL 93.475856
AMD 416.380642
AOA 1045.760713
ARS 1688.928865
AUD 1.62924
AWG 2.051935
AZN 1.942914
BAM 1.953841
BBD 2.294689
BDT 140.529083
BHD 0.429967
BIF 3396.17954
BMD 1.139173
BND 1.470525
BOB 12.56035
BRL 5.780619
BSD 1.139253
BTN 109.963733
BWP 15.492397
BYN 3.287703
BYR 22327.784586
BZD 2.291292
CAD 1.603431
CDF 2574.530657
CHF 0.929561
CLF 0.027128
CLP 1067.655673
CNY 7.715592
CNH 7.715622
COP 3666.199446
CRC 516.879425
CUC 1.139173
CUP 30.188076
CVE 110.154541
CZK 24.186238
DJF 202.878343
DKK 7.475678
DOP 66.214765
DZD 151.647825
EGP 58.439328
ERN 17.08759
ETB 183.887398
FJD 2.556534
FKP 0.85166
GBP 0.853236
GEL 2.996121
GGP 0.85166
GHS 13.232673
GIP 0.85166
GMD 83.734331
GNF 9995.976432
GTQ 8.691247
GYD 238.319976
HKD 8.93268
HNL 30.516935
HRK 7.533806
HTG 148.963241
HUF 364.503375
IDR 20470.19265
ILS 3.500245
IMP 0.85166
INR 110.110894
IQD 1492.529554
IRR 1566647.232079
ISK 143.410726
JEP 0.85166
JMD 180.479023
JOD 0.807646
JPY 186.237703
KES 147.534026
KGS 99.620428
KHR 4597.470555
KMF 492.122132
KRW 1677.738898
KWD 0.352905
KYD 0.949448
KZT 532.663528
LAK 25797.018549
LBP 102022.348256
LKR 382.916027
LRD 206.206888
LSL 18.701665
LTL 3.363681
LVL 0.689074
LYD 7.306673
MAD 10.678592
MDL 20.062794
MGA 4891.073958
MKD 61.508322
MMK 2391.388129
MNT 4090.960131
MOP 9.202032
MRU 45.526348
MUR 53.757852
MVR 17.611752
MWK 1975.536353
MXN 19.895263
MYR 4.657735
MZN 72.804425
NAD 18.702075
NGN 1560.028855
NIO 41.927956
NOK 10.949671
NPR 175.941573
NZD 1.969303
OMR 0.438011
PAB 1.139253
PEN 3.868021
PGK 5.100885
PHP 70.397477
PKR 316.524602
PLN 4.327563
PYG 6897.083879
QAR 4.153235
RON 5.234611
RSD 117.435047
RUB 89.310702
RWF 1676.518854
SAR 4.271472
SBD 9.202102
SCR 15.252961
SDG 684.078591
SEK 11.09426
SGD 1.471156
SLE 27.625007
SOS 651.147056
SRD 42.987252
STD 23578.574557
STN 24.47535
SVC 9.969003
SZL 18.700166
THB 38.533644
TJS 10.526721
TMT 3.998496
TND 3.372418
TRY 53.806313
TTD 7.732213
TWD 36.819883
TZS 3001.717747
UAH 51.063595
UGX 4277.691725
USD 1.139173
UYU 45.75412
UZS 13788.173768
VES 839.523846
VND 29979.037911
VUV 135.588974
WST 3.124487
XAF 655.299891
XAG 0.019494
XAU 0.000279
XCD 3.078671
XCG 2.053332
XDR 0.81309
XOF 655.299891
XPF 119.331742
YER 271.81464
ZAR 18.731872
ZMK 10253.922663
ZMW 21.105743
ZWL 366.813139
  • CMSD

    -0.1000

    22.05

    -0.45%

  • BCC

    -1.6300

    76.07

    -2.14%

  • RYCEF

    -0.5000

    18.25

    -2.74%

  • BCE

    -0.2450

    21.235

    -1.15%

  • RBGPF

    -1.0400

    66.73

    -1.56%

  • NGG

    -1.5350

    82.335

    -1.86%

  • RIO

    -0.8550

    91.425

    -0.94%

  • BTI

    -2.3750

    59.685

    -3.98%

  • GSK

    -0.0400

    50.72

    -0.08%

  • CMSC

    -0.1000

    21.81

    -0.46%

  • AZN

    -0.6300

    169.1

    -0.37%

  • RELX

    -0.0250

    32.715

    -0.08%

  • VOD

    -0.1250

    15.385

    -0.81%

  • BP

    0.9250

    44.245

    +2.09%

  • JRI

    0.0150

    12.935

    +0.12%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Novak--TPP