The Prague Post - AI agents open door to new hacking threats

EUR -
AED 4.246253
AFN 73.412301
ALL 96.383428
AMD 432.970609
ANG 2.06934
AOA 1060.262144
ARS 1636.671131
AUD 1.648055
AWG 2.081213
AZN 1.946815
BAM 1.945334
BBD 2.33932
BDT 140.653282
BGN 1.905057
BHD 0.436402
BIF 3446.855486
BMD 1.156229
BND 1.488273
BOB 7.947244
BRL 6.101771
BSD 1.161523
BTN 105.632694
BWP 15.762816
BYN 3.41797
BYR 22662.097436
BZD 2.336005
CAD 1.566274
CDF 2569.722857
CHF 0.900674
CLF 0.027015
CLP 1066.36766
CNY 7.974226
CNH 8.004091
COP 4362.095325
CRC 554.601187
CUC 1.156229
CUP 30.640081
CVE 109.674946
CZK 24.417371
DJF 206.830097
DKK 7.470491
DOP 69.151867
DZD 152.372523
EGP 61.02618
ERN 17.343442
ETB 180.155581
FJD 2.559256
FKP 0.862058
GBP 0.865959
GEL 3.150736
GGP 0.862058
GHS 12.444051
GIP 0.862058
GMD 84.98315
GNF 10184.667415
GTQ 8.823529
GYD 240.615484
HKD 9.03672
HNL 30.742646
HRK 7.534454
HTG 152.373232
HUF 398.075938
IDR 19611.964118
ILS 3.599232
IMP 0.862058
INR 106.678528
IQD 1521.522412
IRR 1527032.248961
ISK 145.103668
JEP 0.862058
JMD 181.898769
JOD 0.819778
JPY 183.205133
KES 149.326829
KGS 101.113018
KHR 4660.899182
KMF 490.241182
KPW 1040.60617
KRW 1720.718026
KWD 0.356095
KYD 0.96794
KZT 573.853122
LAK 24871.630399
LBP 104011.02834
LKR 361.341797
LRD 209.890783
LSL 19.427998
LTL 3.414045
LVL 0.699391
LYD 7.401283
MAD 10.725596
MDL 20.088161
MGA 4836.729426
MKD 61.623919
MMK 2428.164112
MNT 4126.69093
MOP 9.354947
MRU 46.482626
MUR 54.262112
MVR 17.875451
MWK 2014.048286
MXN 20.681499
MYR 4.582152
MZN 73.93
NAD 19.427914
NGN 1617.726717
NIO 42.741651
NOK 11.176709
NPR 170.6918
NZD 1.957271
OMR 0.444569
PAB 1.150112
PEN 3.961388
PGK 5.002452
PHP 68.773679
PKR 324.431942
PLN 4.278278
PYG 7599.172804
QAR 4.194036
RON 5.096773
RSD 117.417397
RUB 90.472962
RWF 1694.125658
SAR 4.34048
SBD 9.302077
SCR 17.218673
SDG 695.47418
SEK 10.692914
SGD 1.479857
SHP 0.867472
SLE 28.356498
SLL 24245.552932
SOS 662.58244
SRD 43.539555
STD 23931.615425
STN 24.610458
SVC 10.162568
SYP 127.855757
SZL 19.43339
THB 37.069297
TJS 11.058008
TMT 4.058365
TND 3.378921
TOP 2.783923
TRY 50.971075
TTD 7.87029
TWD 36.881429
TZS 2983.072234
UAH 50.753615
UGX 4244.166295
USD 1.156229
UYU 45.246572
UZS 14025.542285
VES 491.561711
VND 30382.819662
VUV 138.024512
WST 3.168634
XAF 658.922967
XAG 0.013856
XAU 0.000227
XCD 3.124768
XCG 2.093286
XDR 0.819482
XOF 658.920105
XPF 119.331742
YER 275.760792
ZAR 19.361074
ZMK 10407.458324
ZMW 22.456987
ZWL 372.305415
  • CMSC

    -0.1050

    23.185

    -0.45%

  • CMSD

    -0.0100

    23.2

    -0.04%

  • BCC

    -3.6800

    71.73

    -5.13%

  • GSK

    -0.1150

    54.4

    -0.21%

  • NGG

    -1.2300

    88.65

    -1.39%

  • RBGPF

    0.1000

    82.5

    +0.12%

  • RIO

    -2.1600

    88.03

    -2.45%

  • BCE

    -0.3850

    25.685

    -1.5%

  • RYCEF

    -0.2000

    17

    -1.18%

  • JRI

    -0.1840

    12.386

    -1.49%

  • RELX

    -0.6810

    35

    -1.95%

  • AZN

    -3.5150

    190.795

    -1.84%

  • VOD

    -0.3450

    14.165

    -2.44%

  • BP

    -0.0600

    40.4

    -0.15%

  • BTI

    -0.0700

    57.79

    -0.12%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Novak--TPP