The Prague Post - AI agents open door to new hacking threats

EUR -
AED 4.268357
AFN 76.142948
ALL 92.050313
AMD 422.869922
ANG 2.080171
AOA 1066.943234
ARS 1756.965801
AUD 1.610654
AWG 2.092046
AZN 1.976378
BAM 1.954728
BBD 2.340017
BDT 142.701744
BGN 1.971597
BHD 0.438064
BIF 3476.123644
BMD 1.162248
BND 1.471006
BOB 14.494114
BRL 5.958377
BSD 1.161873
BTN 109.714306
BWP 15.555603
BYN 3.57324
BYR 22780.053692
BZD 2.336619
CAD 1.605756
CDF 2649.924737
CHF 0.940719
CLF 0.027508
CLP 1086.155915
CNY 7.800194
CNH 7.798054
COP 3624.411145
CRC 527.315364
CUC 1.162248
CUP 30.799562
CVE 110.205039
CZK 24.191485
DJF 206.554702
DKK 7.474992
DOP 68.772878
DZD 154.790017
EGP 59.181065
ERN 17.433715
ETB 188.400404
FJD 2.549448
FKP 0.859755
GBP 0.858326
GEL 3.027647
GGP 0.859755
GHS 13.215809
GIP 0.859755
GMD 86.00583
GNF 10212.663108
GTQ 8.869174
GYD 243.06775
HKD 9.111615
HNL 31.172174
HRK 7.53439
HTG 151.937986
HUF 363.295144
IDR 20553.187219
ILS 3.498888
IMP 0.859755
INR 109.909401
IQD 1521.965372
IRR 1597625.602667
ISK 140.41107
JEP 0.859755
JMD 184.510404
JOD 0.823977
JPY 179.409218
KES 150.441598
KGS 101.638331
KHR 4704.460608
KMF 492.792618
KPW 1046.023215
KRW 1563.792187
KWD 0.358995
KYD 0.968169
KZT 527.730599
LAK 26036.505958
LBP 104040.345524
LKR 381.172448
LRD 203.319377
LSL 18.575473
LTL 3.431815
LVL 0.703032
LYD 7.385014
MAD 10.903867
MDL 20.069994
MGA 4975.314405
MKD 61.491279
MMK 2440.417897
MNT 4180.641194
MOP 9.382455
MRU 46.672807
MUR 54.497585
MVR 17.968293
MWK 2014.612544
MXN 19.664811
MYR 4.70249
MZN 74.266838
NAD 18.574914
NGN 1536.317256
NIO 42.757656
NOK 10.772594
NPR 175.543245
NZD 1.979035
OMR 0.446883
PAB 1.161763
PEN 3.897862
PGK 5.162169
PHP 72.884444
PKR 322.667229
PLN 4.310021
PYG 6921.204495
QAR 4.223202
RON 5.250914
RSD 117.345195
RUB 99.883403
RWF 1713.674986
SAR 4.365225
SBD 9.298576
SCR 16.036208
SDG 699.091581
SEK 11.157902
SGD 1.471255
SHP 0.86107
SLE 28.64874
SLL 24371.750933
SOS 663.941615
SRD 43.868461
STD 24056.179525
STN 24.486782
SVC 10.165425
SYP 15111.543672
SZL 18.571975
THB 38.202755
TJS 10.729362
TMT 4.067867
TND 3.390955
TOP 2.798413
TRY 56.288124
TTD 7.886675
TWD 36.633929
TZS 3073.599016
UAH 51.640325
UGX 4391.610586
USD 1.162248
UYU 46.764556
UZS 13697.488462
VES 937.209875
VND 30241.683524
VUV 137.10706
WST 3.159124
XAF 655.603116
XAG 0.017566
XAU 0.000264
XCD 3.141032
XCG 2.093852
XDR 0.821769
XOF 655.603116
XPF 119.331742
YER 275.452093
ZAR 18.587355
ZMK 10461.621664
ZMW 22.277783
ZWL 374.243265
  • BCC

    2.0900

    79.21

    +2.64%

  • CMSC

    -0.1100

    20.81

    -0.53%

  • JRI

    -0.0700

    12.14

    -0.58%

  • CMSD

    -0.0700

    20.69

    -0.34%

  • RIO

    0.4300

    103.27

    +0.42%

  • BCE

    -0.1400

    23.67

    -0.59%

  • BTI

    -0.6200

    55.35

    -1.12%

  • NGG

    -0.0500

    78.12

    -0.06%

  • BP

    0.2300

    43.81

    +0.52%

  • GSK

    -0.9800

    49.89

    -1.96%

  • RELX

    -1.1400

    35.51

    -3.21%

  • RBGPF

    0.0000

    70

    0%

  • VOD

    0.3200

    16.9

    +1.89%

  • RYCEF

    0.1400

    19.92

    +0.7%

  • AZN

    -2.0700

    162.7

    -1.27%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Novak--TPP