Dubai Telegraph - AI agents open door to new hacking threats

EUR -
AED 4.186804
AFN 72.962441
ALL 94.259056
AMD 418.549568
ANG 2.041136
AOA 1045.418899
ARS 1684.10666
AUD 1.651889
AWG 2.052077
AZN 1.936931
BAM 1.955487
BBD 2.296633
BDT 140.257564
BGN 1.927676
BHD 0.429931
BIF 3386.658257
BMD 1.140043
BND 1.475464
BOB 7.880051
BRL 5.900179
BSD 1.140318
BTN 107.028002
BWP 15.497201
BYN 3.307171
BYR 22344.835632
BZD 2.293293
CAD 1.616934
CDF 2587.896628
CHF 0.921609
CLF 0.026661
CLP 1049.283409
CNY 7.756679
CNH 7.75807
COP 3917.562706
CRC 517.717184
CUC 1.140043
CUP 30.21113
CVE 110.246881
CZK 24.264557
DJF 203.065532
DKK 7.474507
DOP 66.999283
DZD 151.982519
EGP 56.441918
ERN 17.10064
ETB 183.847154
FJD 2.583449
FKP 0.86269
GBP 0.862499
GEL 3.015381
GGP 0.86269
GHS 12.857451
GIP 0.86269
GMD 83.222763
GNF 9991.401736
GTQ 8.699608
GYD 238.651244
HKD 8.940488
HNL 30.510119
HRK 7.535342
HTG 149.03616
HUF 354.147428
IDR 20362.5295
ILS 3.418629
IMP 0.86269
INR 107.599675
IQD 1493.761052
IRR 1567615.623977
ISK 143.998889
JEP 0.86269
JMD 179.591272
JOD 0.808274
JPY 184.289059
KES 147.646835
KGS 99.696357
KHR 4577.267802
KMF 494.7783
KPW 1026.03877
KRW 1752.35789
KWD 0.35298
KYD 0.95029
KZT 553.271497
LAK 25028.996263
LBP 102117.195723
LKR 383.315495
LRD 207.715883
LSL 18.744002
LTL 3.366249
LVL 0.689601
LYD 7.319797
MAD 10.692496
MDL 20.218652
MGA 4823.143858
MKD 61.655153
MMK 2393.462693
MNT 4081.628965
MOP 9.21159
MRU 45.50872
MUR 54.39115
MVR 17.613684
MWK 1977.361744
MXN 19.968844
MYR 4.661976
MZN 72.849226
NAD 18.744002
NGN 1572.118647
NIO 41.963287
NOK 11.298147
NPR 171.247607
NZD 2.018041
OMR 0.438339
PAB 1.140368
PEN 3.888378
PGK 5.004156
PHP 69.892026
PKR 317.357353
PLN 4.286982
PYG 6959.856149
QAR 4.156517
RON 5.241007
RSD 117.374218
RUB 88.643027
RWF 1670.006102
SAR 4.282215
SBD 9.179569
SCR 16.010093
SDG 684.025293
SEK 11.076665
SGD 1.475445
SHP 0.851157
SLE 28.272923
SLL 23906.128197
SOS 651.724331
SRD 42.546623
STD 23596.580793
STN 24.496082
SVC 9.97736
SYP 126.011304
SZL 18.733003
THB 38.047216
TJS 10.553828
TMT 3.990149
TND 3.379908
TOP 2.74495
TRY 53.154875
TTD 7.749624
TWD 36.346152
TZS 2989.981828
UAH 51.183064
UGX 4185.220382
USD 1.140043
UYU 45.774685
UZS 13697.40965
VES 707.684868
VND 29983.121282
VUV 136.749145
WST 3.175585
XAF 655.852087
XAG 0.019615
XAU 0.000282
XCD 3.081022
XCG 2.055071
XDR 0.816787
XOF 655.849211
XPF 119.331742
YER 272.042682
ZAR 18.768497
ZMK 10261.75068
ZMW 20.541075
ZWL 367.093263
  • RYCEF

    0.7000

    18.7

    +3.74%

  • CMSC

    -0.0860

    21.96

    -0.39%

  • RELX

    0.1600

    31.08

    +0.51%

  • RIO

    -0.4850

    94.625

    -0.51%

  • BP

    -0.3600

    37.36

    -0.96%

  • NGG

    -0.1200

    83.3

    -0.14%

  • AZN

    2.9200

    188.6

    +1.55%

  • GSK

    0.6900

    52.58

    +1.31%

  • RBGPF

    0.0000

    61.3

    0%

  • BTI

    0.3150

    62.795

    +0.5%

  • VOD

    -0.0350

    13.825

    -0.25%

  • CMSD

    -0.1000

    21.83

    -0.46%

  • BCE

    -0.2100

    22.99

    -0.91%

  • JRI

    0.1700

    12.75

    +1.33%

  • BCC

    0.0400

    79.8

    +0.05%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

S.Al-Balushi--DT