-
Russian ambassador slams EU frozen assets plan for Ukraine
-
2026 World Cup draw is kind to favorites as Trump takes limelight
-
WHO chief upbeat on missing piece of pandemic treaty
-
US vaccine panel upends hepatitis B advice in latest Trump-era shift
-
Ancelotti says Brazil have 'difficult' World Cup group with Morocco
-
Kriecmayr wins weather-disrupted Beaver Creek super-G
-
Ghostwriters, polo shirts, and the fall of a landmark pesticide study
-
Mixed day for global stocks as market digest huge Netflix deal
-
Fighting erupts in DR Congo a day after peace deal signed
-
England boss Tuchel wary of 'surprise' in World Cup draw
-
10 university students die in Peru restaurant fire
-
'Sinners' tops Critics Choice nominations
-
Netflix's Warner Bros. acquisition sparks backlash
-
France probes mystery drone flight over nuclear sub base
-
Frank Gehry: five key works
-
US Supreme Court to weigh Trump bid to end birthright citizenship
-
Frank Gehry, master architect with a flair for drama, dead at 96
-
'It doesn't make sense': Trump wants to rename American football
-
A day after peace accord signed, shelling forces DRC locals to flee
-
Draw for 2026 World Cup kind to favorites as Trump takes center stage
-
Netflix to buy Warner Bros. in deal of the decade
-
US sanctions equate us with drug traffickers: ICC dep. prosecutor
-
Migration and crime fears loom over Chile's presidential runoff
-
French officer charged after police fracture woman's skull
-
Fresh data show US consumers still strained by inflation
-
Eurovision reels from boycotts over Israel
-
Trump takes centre stage as 2026 World Cup draw takes place
-
Trump all smiles as he wins FIFA's new peace prize
-
US panel votes to end recommending all newborns receive hepatitis B vaccine
-
Title favourite Norris reflects on 'positive' Abu Dhabi practice
-
Stocks consolidate as US inflation worries undermine Fed rate hopes
-
Volcanic eruptions may have brought Black Death to Europe
-
Arsenal the ultimate test for in-form Villa, says Emery
-
Emotions high, hope alive after Nigerian school abduction
-
Another original Hermes Birkin bag sells for $2.86 mn
-
11 million flock to Notre-Dame in year since rising from devastating fire
-
Gymnast Nemour lifts lid on 'humiliation, tears' on way to Olympic gold
-
Lebanon president says country does not want war with Israel
-
France takes anti-drone measures after flight over nuclear sub base
-
Signing up to DR Congo peace is one thing, delivery another
-
'Amazing' figurines find in Egyptian tomb solves mystery
-
Palestinians say Israeli army killed man in occupied West Bank
-
McLaren will make 'practical' call on team orders in Abu Dhabi, says boss Brown
-
Stocks rise as investors look to more Fed rate cuts
-
Norris completes Abu Dhabi practice 'double top' to boost title bid
-
Chiba leads Liu at skating's Grand Prix Final
-
Meta partners with news outlets to expand AI content
-
Mainoo 'being ruined' at Man Utd: Scholes
-
Guardiola says broadcasters owe him wine after nine-goal thriller
-
Netflix to buy Warner Bros. Discovery in deal of the decade
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
F.Wilson--AT