The Prague Post - AI agents open door to new hacking threats

EUR -
AED 4.276788
AFN 76.286791
ALL 96.636249
AMD 442.910615
ANG 2.084627
AOA 1067.886876
ARS 1692.643459
AUD 1.744335
AWG 2.097635
AZN 1.978078
BAM 1.955522
BBD 2.345456
BDT 142.309749
BGN 1.955701
BHD 0.439071
BIF 3447.179863
BMD 1.164544
BND 1.499874
BOB 8.046786
BRL 6.278757
BSD 1.164529
BTN 105.169034
BWP 15.561585
BYN 3.388858
BYR 22825.06798
BZD 2.342067
CAD 1.616329
CDF 2529.968312
CHF 0.931518
CLF 0.026244
CLP 1029.52717
CNY 8.126192
CNH 8.119395
COP 4283.741215
CRC 578.415208
CUC 1.164544
CUP 30.860424
CVE 110.249311
CZK 24.252275
DJF 206.962396
DKK 7.471739
DOP 74.145947
DZD 151.35086
EGP 55.09046
ERN 17.468164
ETB 181.360848
FJD 2.656436
FKP 0.866894
GBP 0.867131
GEL 3.126789
GGP 0.866894
GHS 12.548053
GIP 0.866894
GMD 85.612324
GNF 10193.549452
GTQ 8.928691
GYD 243.633239
HKD 9.080295
HNL 30.715179
HRK 7.533669
HTG 152.411114
HUF 386.79348
IDR 19632.236915
ILS 3.673998
IMP 0.866894
INR 105.122656
IQD 1525.510871
IRR 49056.428177
ISK 146.01028
JEP 0.866894
JMD 183.603873
JOD 0.825646
JPY 184.434117
KES 150.226695
KGS 101.837421
KHR 4687.312868
KMF 492.601908
KPW 1048.123187
KRW 1705.498568
KWD 0.358494
KYD 0.970454
KZT 594.425413
LAK 25171.418093
LBP 104278.688407
LKR 360.427164
LRD 209.618371
LSL 19.107799
LTL 3.438596
LVL 0.704421
LYD 6.3281
MAD 10.730573
MDL 19.907911
MGA 5399.231686
MKD 61.518813
MMK 2445.141875
MNT 4148.405657
MOP 9.352369
MRU 46.325408
MUR 54.116344
MVR 18.004214
MWK 2019.703923
MXN 20.753809
MYR 4.714086
MZN 74.398621
NAD 19.106979
NGN 1656.587773
NIO 42.853902
NOK 11.712981
NPR 168.26861
NZD 2.027577
OMR 0.447757
PAB 1.164529
PEN 3.911943
PGK 4.971293
PHP 69.35911
PKR 325.893526
PLN 4.214049
PYG 7903.875274
QAR 4.245696
RON 5.088589
RSD 117.382599
RUB 91.417574
RWF 1697.843816
SAR 4.367628
SBD 9.467996
SCR 15.9742
SDG 700.470236
SEK 10.716249
SGD 1.499815
SHP 0.87371
SLE 28.123561
SLL 24419.910525
SOS 664.405455
SRD 44.592677
STD 24103.715488
STN 24.496409
SVC 10.18955
SYP 12879.364735
SZL 19.100282
THB 36.647016
TJS 10.824267
TMT 4.075905
TND 3.409315
TOP 2.803943
TRY 50.281063
TTD 7.904841
TWD 36.760937
TZS 2923.005763
UAH 50.297443
UGX 4145.39231
USD 1.164544
UYU 45.103582
UZS 14030.003523
VES 384.251308
VND 30601.312441
VUV 140.83932
WST 3.235712
XAF 655.858039
XAG 0.012776
XAU 0.000252
XCD 3.147239
XCG 2.098801
XDR 0.81629
XOF 655.86367
XPF 119.331742
YER 277.630706
ZAR 19.148569
ZMK 10482.294377
ZMW 22.969548
ZWL 374.982785
  • SCS

    0.0200

    16.14

    +0.12%

  • CMSC

    -0.0400

    23.35

    -0.17%

  • JRI

    -0.0200

    13.8

    -0.14%

  • GSK

    0.8150

    50.715

    +1.61%

  • AZN

    1.6000

    96.11

    +1.66%

  • BCE

    0.5550

    24.275

    +2.29%

  • RBGPF

    0.0000

    81.57

    0%

  • BTI

    0.8150

    57.435

    +1.42%

  • NGG

    0.8600

    78.94

    +1.09%

  • CMSD

    -0.0310

    23.869

    -0.13%

  • RIO

    2.0450

    85.635

    +2.39%

  • BP

    0.9150

    36.275

    +2.52%

  • RYCEF

    -0.1800

    17.1

    -1.05%

  • VOD

    0.1800

    13.36

    +1.35%

  • BCC

    0.3550

    84.225

    +0.42%

  • RELX

    -0.5500

    41.64

    -1.32%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Novak--TPP