-
Bayern and Kane gambling with house money as Gladbach come to town
-
Turkey invests in foreign legion to deliver LA Olympics gold
-
Galthie's France blessed with unprecedented talent: Saint-Andre
-
Voice coach to the stars says Aussie actors nail tricky accents
-
Rahm rejection of DP World Tour deal 'a shame' - McIlroy
-
Israel keeps up Lebanon strikes as ground forces advance
-
China prioritises energy and diplomacy over Iran support
-
Canada PM Carney says can't rule out military participation in Iran war
-
Verstappen says new Red Bull car gave him 'goosebumps'
-
Swiss to vote on creating giant 'climate fund'
-
Google to open German centre for 'AI development'
-
Winter Paralympics to start with icy blast as Ukraine lead ceremony boycott
-
Sci-fi without AI: Oscar nominated 'Arco' director prefers human touch
-
Ex-guerrillas battle low support in Colombia election
-
'She's coming back': Djokovic predicts Serena return
-
Hamilton vows 'no holding back' in his 20th Formula One season
-
Two-thirds of Cuba, including Havana, hit by blackout
-
US sinks Iranian warship off Sri Lanka as war spreads
-
After oil, US moves to secure access to Venezuelan minerals
-
Arteta hits back at Brighton criticism after Arsenal boost title bid
-
Carrick says 'defeat hurts' after first loss as Man Utd boss
-
Ecuador expels Cuba envoy, rest of mission
-
Arsenal stretch lead at top of Premier League as Man City falter
-
Title race not over vows Guardiola after Man City held by Forest
-
Rosenior hails 'world class' Joao Pedro after hat-trick crushes Villa
-
Brazil ratifies EU-Mercosur trade deal
-
Real Sociedad edge rivals Athletic to reach Copa del Rey final
-
Chelsea boost top four push as Joao Pedro treble routs Villa
-
Leverkusen sink Hamburg to keep in touch with top four
-
Love match: WTA No. 1 Sabalenka announces engagement
-
Man City falter as Premier League leaders Arsenal go seven points clear
-
Man City title bid rocked by Forest draw
-
Defending champ Draper ready to ramp up return at Indian Wells
-
Arsenal extend lead in title race after Saka sinks Brighton
-
US, European stocks rise as oil prices steady; Asian indexes tumble
-
Trump rates Iran war as '15 out of 10'
-
Nepal votes in key post-uprising polls
-
US Fed warns 'economic uncertainty' weighing on consumers
-
Florida family sues Google after AI chatbot allegedly coached suicide
-
Alcaraz unbeaten run under threat from Sinner, Djokovic at Indian Wells
-
Iran's supreme leader gone, but opposition still at war with itself
-
Mideast war rekindles European fears over soaring gas prices
-
'Miracle to walk' says golfer after lift shaft fall
-
'Nothing is working': Gulf travel turmoil hits Berlin tourism fair
-
Harvey Weinstein rape retrial to start April 14: publicist
-
No choke but 'walloping', South Africa coach says of T20 flop
-
Bayer gets preliminary approval for weedkiller class settlement
-
Russia to free two Hungarian-Ukrainian POWs, Putin says
-
Michelangelo's works hidden in 'secret room', researcher says
-
Adidas shares slump on outlook, Mideast war casts shadow
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
C.Kreuzer--VB