Zürcher Nachrichten - AI agents open door to new hacking threats

EUR -
AED 4.185954
AFN 72.947589
ALL 94.294632
AMD 417.830324
ANG 2.040717
AOA 1045.205368
ARS 1683.774482
AUD 1.652987
AWG 2.051656
AZN 1.936427
BAM 1.957791
BBD 2.287406
BDT 139.692031
BGN 1.927281
BHD 0.42823
BIF 3384.485685
BMD 1.139809
BND 1.473518
BOB 7.848117
BRL 5.900221
BSD 1.13574
BTN 107.155009
BWP 15.497553
BYN 3.232172
BYR 22340.254248
BZD 2.284202
CAD 1.61687
CDF 2587.365958
CHF 0.921797
CLF 0.026609
CLP 1047.267556
CNY 7.755088
CNH 7.754826
COP 3916.759484
CRC 516.91877
CUC 1.139809
CUP 30.204936
CVE 110.378679
CZK 24.26106
DJF 202.242967
DKK 7.474986
DOP 66.927167
DZD 151.937634
EGP 56.431257
ERN 17.097133
ETB 179.123465
FJD 2.582924
FKP 0.862513
GBP 0.862647
GEL 3.014799
GGP 0.862513
GHS 12.774212
GIP 0.862513
GMD 83.206091
GNF 9951.987623
GTQ 8.664924
GYD 237.635784
HKD 8.938364
HNL 30.389498
HRK 7.53345
HTG 148.444185
HUF 354.030908
IDR 20395.740282
ILS 3.415266
IMP 0.862513
INR 107.583366
IQD 1487.838853
IRR 1567294.214566
ISK 144.02629
JEP 0.862513
JMD 178.999641
JOD 0.808094
JPY 184.143532
KES 147.607196
KGS 99.676239
KHR 4573.750637
KMF 494.677183
KPW 1025.8284
KRW 1754.256722
KWD 0.352884
KYD 0.946479
KZT 550.449323
LAK 25242.107599
LBP 101708.364882
LKR 382.76589
LRD 206.698345
LSL 18.808453
LTL 3.36556
LVL 0.689459
LYD 7.293319
MAD 10.692259
MDL 20.159851
MGA 4841.859197
MKD 61.637914
MMK 2392.971959
MNT 4080.792105
MOP 9.171825
MRU 45.111273
MUR 54.380594
MVR 17.610087
MWK 1969.376428
MXN 19.991963
MYR 4.663073
MZN 72.832523
NAD 18.808453
NGN 1566.52989
NIO 41.79341
NOK 11.286559
NPR 171.447061
NZD 2.017627
OMR 0.438256
PAB 1.135775
PEN 3.886652
PGK 4.984002
PHP 69.821231
PKR 316.069401
PLN 4.286759
PYG 6939.995289
QAR 4.139964
RON 5.239589
RSD 117.401001
RUB 87.877339
RWF 1668.974951
SAR 4.264217
SBD 9.177687
SCR 16.007841
SDG 683.885259
SEK 11.07277
SGD 1.475243
SHP 0.850982
SLE 28.280114
SLL 23901.2267
SOS 649.051375
SRD 42.537564
STD 23591.742763
STN 24.524612
SVC 9.938279
SYP 125.985468
SZL 18.805873
THB 38.063948
TJS 10.49996
TMT 3.989331
TND 3.372273
TOP 2.744387
TRY 53.143533
TTD 7.713978
TWD 36.32035
TZS 2986.796222
UAH 51.068251
UGX 4202.346435
USD 1.139809
UYU 45.566929
UZS 13642.871264
VES 707.539771
VND 29970.704864
VUV 136.721107
WST 3.174934
XAF 656.615967
XAG 0.019708
XAU 0.000282
XCD 3.080391
XCG 2.046917
XDR 0.81662
XOF 656.615967
XPF 119.331742
YER 271.986885
ZAR 18.756463
ZMK 10259.644484
ZMW 20.499663
ZWL 367.017998
  • CMSC

    -0.0190

    22.046

    -0.09%

  • JRI

    0.0100

    12.58

    +0.08%

  • CMSD

    -0.0900

    21.93

    -0.41%

  • GSK

    0.8000

    51.89

    +1.54%

  • BCE

    0.0000

    23.2

    0%

  • RIO

    1.0800

    95.11

    +1.14%

  • BCC

    2.1000

    79.76

    +2.63%

  • BTI

    1.0900

    62.48

    +1.74%

  • AZN

    2.6600

    185.68

    +1.43%

  • NGG

    0.5900

    83.42

    +0.71%

  • RBGPF

    0.0000

    61.3

    0%

  • BP

    -0.1400

    37.72

    -0.37%

  • RYCEF

    0.7000

    18.7

    +3.74%

  • RELX

    -0.2300

    30.92

    -0.74%

  • VOD

    0.0500

    13.86

    +0.36%

AI agents open door to new hacking threats
AI agents open door to new hacking threats / Photo: Lionel BONAVENTURE - AFP/File

AI agents open door to new hacking threats

Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.

Text size:

AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.

But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.

"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.

"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."

These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.

But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.

"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.

Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."

Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.

- AI 'off track' -

Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."

But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.

Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.

Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.

Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.

OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.

Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.

"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.

In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.

"They only get better," Rehberger said of hacker tactics.

Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.

Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.

"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.

"It just goes off track."

R.Schmid--NZN