-
Australia PM welcomes Iran ceasefire, says Trump threats not 'appropriate'
-
Nigeria sweats in heatwave as Iran war drives up costs to stay cool
-
'Pinprick of light': Artemis crew witnesses meteorite impacts on Moon
-
German factory orders rise in February but energy shock looms
-
China says investigating 'malicious' cyberbullying of teen diving star
-
North Korea fires two rounds of ballistic missiles: Seoul military
-
Taiwan opposition leader says China visit to sow 'seeds of peace'
-
Jet fuel supplies to take 'months' to recover from war disruption: IATA
-
How did Pakistan broker a temporary truce between Iran and the US?
-
North Korea fires multiple ballistic missiles in two rounds: Seoul military
-
Rockets comeback sinks Phoenix on Durant return
-
'Ketamine Queen' to be sentenced over Matthew Perry death
-
Vietnam's To Lam bets big on building blitz
-
Sooryavanshi, 15, hailed as 'amazing, fearless' after acing Bumrah test
-
Pakistan to host US-Iran ceasefire talks Friday
-
Middle East war: ceasefire reactions
-
North Korea fires multiple ballistic missiles towards East Sea
-
Both sides claim victory after US, Iran agree to 11th-hour truce
-
Unbeaten legend Winx's $7 million foal retires without racing
-
Trump to AFP: Iran deal 'total and complete victory' for US
-
Solar push helps Pakistan temper Gulf energy shock
-
Crude prices plunge, stocks surge as US and Iran agree ceasefire
-
Wave of nostalgia as 2000s TV makes a comeback
-
Iraqi armed group releases US journalist
-
Forest's Igor Jesus eyes Europa League 'dream', Villa brace for Bologna in quarters
-
In-demand prop De Lutiis rebuffs Ireland to commit to Australia
-
US, Iran agree to 11th-hour truce after Trump apocalyptic threats
-
Marijuana Rescheduling Countdown: Why the "Order of Operations" and Todd Blanche's Appointment Define the Path to Schedule III
-
New Birth Injury Resource Center Launches as Data Shows Thousands of Newborns Face Preventable Complications Each Year
-
Kingfisher Appoints Sharon G.K. Singh to Board of Directors
-
Rad Source Technologies Activates a Wealth of Peer-Reviewed Data with Bioz Badges to Strengthen Customer Use-Case Visibility
-
Tocvan Announces Addition of Second Drill Rig and Accelerates High-Priority Drill Targets at Flagship Gran Pilar Gold-Silver Project
-
InterContinental Hotels Group PLC Announces Transaction in Own Shares - April 08
-
Trump suspends Iran bombing for two weeks, after apocalyptic threats
-
Latest Anthropic AI model finds cracks in software defenses
-
McIlroy chases Masters repeat at lightning-fast Augusta
-
Arsenal's Raya hailed as 'world's best keeper' after denying Sporting
-
Bayern's Kompany praises 'special' Neuer display in win at Real Madrid
-
Diaz, Kane give Bayern vital Champions League win at Real
-
Havertz strikes late as Arsenal steal Champions League advantage against Sporting
-
Pakistan makes last-minute bid to avert Trump threat to destroy Iran
-
Artemis II crew basks in glow of lunar flyby en route to Earth
-
Global stocks mostly fall ahead of Trump's deadline for Iran
-
Trump weighs plea for Iran deadline extension
-
Artemis and ISS astronauts share celestial call
-
Former Romania coach Lucescu dies aged 80
-
'Nice to get a 2nd chance': Slot tips Liverpool to bounce back against PSG
-
Iran says ready for anything after Trump warns 'whole civilization will die'
-
French couple head home after more than three years in Iranian jail
-
Jaiswal, Sooryavanshi fire Rajasthan to win in rain-hit IPL clash
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
F.Wilson--AT