The Prague Post - AI agents open door to new hacking threats

EUR -
AED 4.24517
AFN 76.755625
ALL 96.609587
AMD 442.411371
ANG 2.069102
AOA 1059.991904
ARS 1641.428559
AUD 1.768715
AWG 2.089352
AZN 1.96548
BAM 1.95585
BBD 2.32916
BDT 141.193629
BGN 1.955737
BHD 0.435824
BIF 3406.408573
BMD 1.155935
BND 1.506823
BOB 8.020206
BRL 6.11628
BSD 1.156515
BTN 102.507635
BWP 15.476536
BYN 3.942148
BYR 22656.320344
BZD 2.32576
CAD 1.620961
CDF 2482.94765
CHF 0.930603
CLF 0.027637
CLP 1084.197186
CNY 8.229851
CNH 8.231486
COP 4339.055245
CRC 580.650087
CUC 1.155935
CUP 30.63227
CVE 110.536275
CZK 24.287458
DJF 205.940437
DKK 7.466997
DOP 74.268724
DZD 150.855237
EGP 54.628986
ERN 17.339021
ETB 177.588819
FJD 2.634371
FKP 0.878628
GBP 0.877395
GEL 3.126794
GGP 0.878628
GHS 12.651325
GIP 0.878628
GMD 84.383361
GNF 10038.909384
GTQ 8.864228
GYD 241.936219
HKD 8.986225
HNL 30.427625
HRK 7.536005
HTG 151.412406
HUF 383.639124
IDR 19300.641877
ILS 3.739738
IMP 0.878628
INR 102.540136
IQD 1514.879964
IRR 48664.851159
ISK 146.202293
JEP 0.878628
JMD 186.150083
JOD 0.81953
JPY 178.195414
KES 149.344418
KGS 101.086035
KHR 4641.077668
KMF 486.648684
KPW 1040.343508
KRW 1683.480377
KWD 0.354976
KYD 0.963687
KZT 605.821987
LAK 25109.667896
LBP 103553.23039
LKR 351.635349
LRD 211.625439
LSL 19.873637
LTL 3.413175
LVL 0.699213
LYD 6.310626
MAD 10.705875
MDL 19.62974
MGA 5195.560538
MKD 61.521525
MMK 2427.102406
MNT 4138.939034
MOP 9.258838
MRU 45.923763
MUR 53.011561
MVR 17.807203
MWK 2005.41636
MXN 21.244912
MYR 4.81214
MZN 73.932929
NAD 19.873637
NGN 1660.627691
NIO 42.553855
NOK 11.710688
NPR 164.022149
NZD 2.047918
OMR 0.444455
PAB 1.15643
PEN 3.9031
PGK 4.882442
PHP 68.165813
PKR 327.000751
PLN 4.235287
PYG 8192.210568
QAR 4.214908
RON 5.084899
RSD 117.170133
RUB 93.919283
RWF 1680.981358
SAR 4.335336
SBD 9.514027
SCR 15.883889
SDG 694.139984
SEK 10.997274
SGD 1.505541
SHP 0.86725
SLE 26.819547
SLL 24239.372387
SOS 659.771181
SRD 44.49944
STD 23925.514704
STN 24.50222
SVC 10.117866
SYP 12780.984651
SZL 19.869972
THB 37.395239
TJS 10.713758
TMT 4.057331
TND 3.413888
TOP 2.707319
TRY 48.825184
TTD 7.843896
TWD 35.812244
TZS 2838.535176
UAH 48.629747
UGX 4059.104333
USD 1.155935
UYU 46.011183
UZS 13894.357132
VES 263.777373
VND 30401.082911
VUV 141.623483
WST 3.260763
XAF 656.027777
XAG 0.022881
XAU 0.000281
XCD 3.123972
XCG 2.084072
XDR 0.815888
XOF 656.022102
XPF 119.331742
YER 275.763163
ZAR 19.816252
ZMK 10404.81256
ZMW 26.163672
ZWL 372.210505
  • CMSD

    0.0600

    24.16

    +0.25%

  • SCS

    -0.0200

    15.74

    -0.13%

  • GSK

    0.7300

    47.36

    +1.54%

  • AZN

    2.9000

    87.48

    +3.32%

  • BTI

    0.8300

    55.42

    +1.5%

  • NGG

    -0.4200

    77.33

    -0.54%

  • RIO

    0.9600

    70.29

    +1.37%

  • BCC

    -0.8100

    69.83

    -1.16%

  • BP

    0.5400

    37.12

    +1.45%

  • CMSC

    0.0400

    23.89

    +0.17%

  • RBGPF

    0.0000

    76

    0%

  • RYCEF

    0.0200

    14.82

    +0.13%

  • JRI

    -0.0600

    13.68

    -0.44%

  • BCE

    -0.2500

    22.94

    -1.09%

  • VOD

    0.1200

    11.7

    +1.03%

  • RELX

    -0.2400

    42.03

    -0.57%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

A.Novak--TPP