-
Downing Street exerted pressure to OK Mandelson: sacked UK official
-
Pope visits Equatorial Guinea on last stop of Africa tour
-
German investor morale lowest in over 3 years on Iran war fallout
-
FedEx faces French 'genocide' complaint over Israel cargoes
-
No Iran delegation sent to US talks yet as truce expiry nears
-
Rover discovers more building blocks of life on Mars
-
Russia, North Korea connect road bridge ahead of summer opening
-
'Strangled': Pakistan faces economic imperative in Iran war peace push
-
Michael Jackson fans pack Hollywood for biopic premiere
-
Turkey arrests 110 coal miners on hunger strike
-
Associated British Foods to spin off Primark clothes brand
-
Pope visits Eq. Guinea on last stop of Africa tour
-
Hello Kitty's parent company to make own video games
-
Di Matteo says 'vital' for faltering Chelsea to add experience
-
Ex-Spurs star Davids condemns 'lack of quality, lack of management'
-
Turkmenistan, the gas giant increasingly dependent on China
-
Romanian AI music sensation Lolita sparks racism debate
-
Timberwolves battle back to stun Nuggets in NBA playoffs
-
Eta appointment 'no surprise' for Union Berlin's ascendant women
-
Democrats eye Virginia gains in war with Trump over US voting map
-
Tourists trickle back to Kashmir, one year after deadly attack
-
Inside the world of ultra-luxury wedding cakes
-
Chinese AI circuit board maker soars on Hong Kong debut
-
Oil prices dip, most stocks rise on lingering Iran peace hopes
-
Tim Cook's time as Apple chief marked by profit absent awe
-
Mitchell, Harden shine as Cavs down Raptors for 2-0 series lead
-
El Salvador's missing thousands buried by official indifference
-
Trump's Fed chair pick to face lawmakers at key confirmation hearing
-
PGA Tour to scrap Hawaii opening events from 2027
-
Amazon invests another $5 bn in Anthropic
-
Israel PM vows 'harsh action' against soldier vandalising Jesus statue in Lebanon
-
New Report Reveals Widespread Misunderstanding of Consumer Messaging App Security Across Government and Critical Infrastructure
-
Wembanyama wins NBA defensive player of the year
-
'The Devil Wears Prada 2' stars reunite for glamorous premiere
-
El Salvador holds mass trial of nearly 500 alleged gang members
-
Apple's Tim Cook to step down as CEO in September
-
West Ham's draw at Palace relegates Wolves, piles pressure on Spurs
-
Canadian tourist killed in Mexico archaeological site shooting
-
Wolves relegated from Premier League
-
Oil jumps on Hormuz tensions, stocks mostly retreat
-
Colombian environmental activist honored amid threats and exile
-
Gun battle traps more than 200 tourists at Rio viewpoint
-
Alcaraz may skip French Open rather than rush injury comeback
-
Top US court to hear case of Catholic schools excluded from state funding
-
Trump Fed chair pick to vow interest rate independence at key hearing
-
EU to host Taliban officials for talks on deporting Afghans
-
Blue Origin probing rocket's failure to deliver satellite
-
Wembanyama 'changing the game as we speak', says Nowitzki
-
Swiss football club turn down Kanye West concert approach
-
Leicester fairytale turns sour as relegation to third tier looms
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
C.Kreuzer--VB