Dubai Telegraph - AI agents open door to new hacking threats

EUR -
AED 4.220543
AFN 72.388508
ALL 96.069869
AMD 433.653783
ANG 2.056852
AOA 1053.656538
ARS 1602.316393
AUD 1.627158
AWG 2.071119
AZN 1.954639
BAM 1.957206
BBD 2.313763
BDT 140.962519
BGN 1.96404
BHD 0.43391
BIF 3412.606207
BMD 1.149026
BND 1.469526
BOB 7.966794
BRL 6.056166
BSD 1.148826
BTN 105.963064
BWP 15.664392
BYN 3.422323
BYR 22520.902917
BZD 2.310571
CAD 1.570287
CDF 2602.543398
CHF 0.905323
CLF 0.026454
CLP 1044.475571
CNY 7.99291
CNH 7.919291
COP 4250.487208
CRC 539.592433
CUC 1.149026
CUP 30.44918
CVE 111.024626
CZK 24.44554
DJF 204.568778
DKK 7.471792
DOP 70.492583
DZD 151.974943
EGP 60.167035
ERN 17.235385
ETB 180.954804
FJD 2.543885
FKP 0.867444
GBP 0.863976
GEL 3.137121
GGP 0.867444
GHS 12.507131
GIP 0.867444
GMD 84.454608
GNF 10082.700083
GTQ 8.805404
GYD 240.474892
HKD 8.997164
HNL 30.412118
HRK 7.536576
HTG 150.569506
HUF 390.656654
IDR 19516.200819
ILS 3.588528
IMP 0.867444
INR 106.008301
IQD 1504.894474
IRR 1517920.347018
ISK 143.202585
JEP 0.867444
JMD 180.709853
JOD 0.814624
JPY 182.897883
KES 148.690295
KGS 100.482161
KHR 4617.336547
KMF 492.931898
KPW 1034.123085
KRW 1713.237502
KWD 0.352234
KYD 0.957296
KZT 554.753459
LAK 24675.3256
LBP 102895.247939
LKR 357.730169
LRD 210.559301
LSL 19.326656
LTL 3.392774
LVL 0.695034
LYD 7.363355
MAD 10.792749
MDL 19.988537
MGA 4782.665625
MKD 61.652816
MMK 2412.542911
MNT 4103.498066
MOP 9.264938
MRU 45.802311
MUR 53.706171
MVR 17.752803
MWK 1991.648479
MXN 20.438007
MYR 4.516248
MZN 73.433763
NAD 19.326656
NGN 1575.923439
NIO 42.270374
NOK 11.140758
NPR 169.547948
NZD 1.964362
OMR 0.441796
PAB 1.148836
PEN 3.96555
PGK 4.953603
PHP 68.630731
PKR 320.913193
PLN 4.270986
PYG 7456.357939
QAR 4.199154
RON 5.094546
RSD 117.398301
RUB 93.501567
RWF 1676.619365
SAR 4.312118
SBD 9.25163
SCR 17.126377
SDG 690.564479
SEK 10.756207
SGD 1.46884
SHP 0.862067
SLE 28.208659
SLL 24094.505996
SOS 655.37664
SRD 43.170617
STD 23782.511268
STN 24.517618
SVC 10.052311
SYP 126.996044
SZL 19.312045
THB 37.157203
TJS 11.028321
TMT 4.02159
TND 3.393138
TOP 2.766577
TRY 50.767309
TTD 7.790666
TWD 36.723435
TZS 2993.211975
UAH 50.645333
UGX 4337.154309
USD 1.149026
UYU 46.703967
UZS 13890.101941
VES 508.678973
VND 30207.884576
VUV 137.383546
WST 3.142832
XAF 656.434409
XAG 0.014252
XAU 0.00023
XCD 3.105299
XCG 2.070406
XDR 0.818715
XOF 656.434409
XPF 119.331742
YER 274.100137
ZAR 19.244818
ZMK 10342.620646
ZMW 22.372271
ZWL 369.985793
  • RBGPF

    0.1000

    82.5

    +0.12%

  • CMSC

    -0.0400

    22.95

    -0.17%

  • NGG

    -0.3300

    90.57

    -0.36%

  • BCC

    1.9150

    71.915

    +2.66%

  • GSK

    0.6250

    54.015

    +1.16%

  • RIO

    1.6850

    89.515

    +1.88%

  • RYCEF

    -0.1500

    16.4

    -0.91%

  • BCE

    0.5221

    25.77

    +2.03%

  • JRI

    -0.0050

    12.585

    -0.04%

  • RELX

    0.3600

    34.5

    +1.04%

  • CMSD

    -0.0050

    22.985

    -0.02%

  • VOD

    0.1600

    14.57

    +1.1%

  • AZN

    2.2500

    192.15

    +1.17%

  • BP

    0.2550

    42.925

    +0.59%

  • BTI

    1.2500

    61.18

    +2.04%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

S.Al-Balushi--DT