Zürcher Nachrichten - AI agents open door to new hacking threats

EUR -
AED 4.240317
AFN 75.613798
ALL 93.083621
AMD 422.304338
AOA 1058.65099
ARS 1729.863941
AUD 1.63662
AWG 2.078049
AZN 1.966429
BAM 1.954423
BBD 2.325762
BDT 142.67949
BHD 0.435489
BIF 3446.098132
BMD 1.154472
BND 1.477659
BOB 13.741379
BRL 5.906976
BSD 1.154687
BTN 109.989518
BWP 15.555907
BYN 3.432982
BYR 22627.646025
BZD 2.322364
CAD 1.609934
CDF 2611.992228
CHF 0.935157
CLF 0.026841
CLP 1056.411264
CNY 7.789916
CNH 7.788897
COP 3623.690519
CRC 524.22617
CUC 1.154472
CUP 30.593501
CVE 110.187856
CZK 24.259377
DJF 205.172641
DKK 7.476145
DOP 67.321992
DZD 153.279508
EGP 57.585512
ERN 17.317076
ETB 186.715352
FJD 2.553114
FKP 0.856331
GBP 0.854713
GEL 3.013068
GGP 0.856331
GHS 13.556568
GIP 0.856331
GMD 84.856485
GNF 10140.856305
GTQ 8.81087
GYD 241.831737
HKD 9.057432
HNL 30.951928
HRK 7.535817
HTG 150.98364
HUF 364.606998
IDR 20526.507465
ILS 3.461279
IMP 0.856331
INR 110.133259
IQD 1512.727812
IRR 1587081.157342
ISK 142.20827
JEP 0.856331
JMD 183.379231
JOD 0.818459
JPY 183.716281
KES 149.365809
KGS 100.958668
KHR 4681.70199
KMF 491.805569
KRW 1637.335322
KWD 0.356743
KYD 0.962318
KZT 538.348431
LAK 26078.516124
LBP 103405.556276
LKR 387.005699
LRD 208.423177
LSL 18.684038
LTL 3.408855
LVL 0.698328
LYD 7.358816
MAD 10.768161
MDL 20.068863
MGA 4945.473339
MKD 61.481956
MMK 2423.870661
MNT 4149.464085
MOP 9.331386
MRU 46.314972
MUR 54.25975
MVR 17.836226
MWK 2002.272162
MXN 19.799721
MYR 4.722482
MZN 73.776479
NAD 18.683957
NGN 1572.009557
NIO 42.490068
NOK 10.961657
NPR 175.981506
NZD 1.962504
OMR 0.443899
PAB 1.154692
PEN 3.900486
PGK 5.105359
PHP 70.2929
PKR 320.577493
PLN 4.303005
PYG 6873.158225
QAR 4.209453
RON 5.242474
RSD 117.329831
RUB 95.245181
RWF 1696.29036
SAR 4.323331
SBD 9.311619
SCR 16.647423
SDG 693.263532
SEK 10.968947
SGD 1.478549
SLE 28.396685
SOS 659.929398
SRD 43.581889
STD 23895.234065
STN 24.482541
SVC 10.103839
SZL 18.680679
THB 38.101605
TJS 10.663842
TMT 4.052196
TND 3.38493
TRY 55.083338
TTD 7.832449
TWD 37.252468
TZS 3059.347785
UAH 51.797563
UGX 4301.007424
USD 1.154472
UYU 46.517634
UZS 13778.234292
VES 872.506333
VND 30195.208254
VUV 137.805149
WST 3.155998
XAF 655.489565
XAG 0.017742
XAU 0.000265
XCD 3.120017
XCG 2.081125
XDR 0.815219
XOF 655.495238
XPF 119.331742
YER 275.226374
ZAR 18.707811
ZMK 10391.663406
ZMW 21.598785
ZWL 371.739428
  • RBGPF

    0.8600

    70.6

    +1.22%

  • CMSC

    -0.1738

    21.57

    -0.81%

  • BCC

    -1.8500

    84.75

    -2.18%

  • NGG

    -1.4000

    79.48

    -1.76%

  • JRI

    -0.0800

    12.73

    -0.63%

  • RIO

    0.8100

    101.91

    +0.79%

  • GSK

    -0.8000

    52.16

    -1.53%

  • BCE

    -0.2100

    22.54

    -0.93%

  • CMSD

    -0.1300

    21.69

    -0.6%

  • AZN

    0.4900

    161.91

    +0.3%

  • RELX

    0.1000

    35.62

    +0.28%

  • RYCEF

    -0.1000

    20.9

    -0.48%

  • VOD

    -0.4400

    15.75

    -2.79%

  • BP

    1.2500

    42.88

    +2.92%

  • BTI

    -2.2800

    57.05

    -4%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

R.Schmid--NZN