-
Solomon Islands says China security pact to remain secret
-
Tharp, 20, breaks 110m hurdles world record at NCAA championships
-
Thailand sentences Chinese Uyghurs to death in 2015 shrine bombing case
-
'Victory' or 'peace': Russian Orthodox believers question Church's war stance
-
Ukrainian mother's agony highlights abuse and weaponisation of draft
-
Swiss to vote on stricter rules for conscientious objection
-
'Resilient' Knicks on brink of NBA title after record rally
-
Suspense surrounds Swiss anti-immigration vote
-
Rising costs and competition threaten GoPro
-
A taste of home: Zimbabwe restaurants revive traditional food
-
AI gold rush upends San Francisco housing market
-
'It just hurts': Spurs search for answers after epic collapse against Knicks
-
World Cup set for kickoff after high ticket prices, visa issues dog buildup
-
Several arrested outside NBA Finals in New York
-
Knicks stage historic comeback to beat Spurs, one win from NBA title
-
The Indian workers training AI robots to take their jobs
-
AI robot cleaners leave the lab for China's living rooms
-
In ageing South Korea, AI dolls care for the elderly
-
S.Korea hits Coupang with record fine over e-commerce data leak
-
Stocks drop, oil rises as Iran and rate worries dog traders
-
Giants under pressure in open Women's T20 World Cup
-
Antonelli seeks sixth straight win at Barcelona Grand Prix
-
Russia's conscripts recount pressure to fight in Ukraine
-
Twenty-two countries tell Iran to stop attacks 'on our soil'
-
ECB set to hike interest rates to tame Iran war inflation surge
-
Pilots demand answers ahead of Air India crash anniversary
-
Iran's World Cup super fans excited for football despite the war
-
Drone rescue highlights US Navy's autonomous push
-
All in on Musk, SpaceX's self-declared 'dream weaver'
-
South Africa brace for Azteca test against Mexico
-
SpaceX on cusp of record IPO that could make Musk a trillionaire
-
G7 summit under tight security on both sides of Lake Geneva
-
Singer Taylor Swift courtside as Knicks duel Spurs in NBA Finals
-
Milestone-man McKenzie ready to 'rip' into Crusaders in Super semi
-
Son keeping 'fired-up' South Koreans calm as World Cup kicks off
-
US renews Iran attacks, Tehran says it closed Strait of Hormuz
-
Macron says trust in France institutions 'at stake' after girl's killing
-
Portugal beat Nigeria in World Cup tune-up despite Ronaldo woes
-
Gordon stars in England World Cup warm-up win after storm delay
-
Canada moves to ban under-16s from social media, regulate AI
-
US renews Iran attacks as Trump vows to hit 'hard'
-
Record lobby cash shapes EU pro-business agenda, campaigners say
-
"I love the inflation": Trump comment on latest price jump sparks backlash
-
South Asia monsoon risks both floods and drought: experts
-
US renews attacks on Iran, vows to hit 'hard'
-
World Cup blends soccer with global music stars
-
Northern Irish police use water cannon on second night of protests
-
Raphinha eager to deliver for Ancelotti as Brazil get set for World Cup bid
-
Trump brushes off latest US inflation jump
-
FIFA boss Infantino defends World Cup ticket prices, brushes off visa row
AI 'agent' fever comes with lurking security threats
Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge.
Powered by a wave of hype, OpenClaw today claims more than three million users worldwide.
The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks.
"We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company.
In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behaviour of six AI agents created with OpenClaw.
They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information.
Many users have posted similar stories of OpenClaw mishaps online.
"When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency.
And the security gaps are not limited to the agents' own mistaken actions.
To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers.
- 'Delete your database' -
AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks.
"As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being used and using that then to interrogate the systems for more information."
Palo Alto's Unit 42 research division said in early March that it had found traces of attempted attacks in the form of hidden instructions for agents added to websites.
One such command ordered any agent who might read it to "delete your database".
Other cybersecurity firms and researchers have warned that attackers could gain access to agents via so-called skills -- downloadable files that users can add to their systems to give them new abilities.
Among such files freely available for download, some include hidden instructions for malicious actions like exfiltrating data.
OpenClaw creator Peter Steinberger says he is well aware of the risks.
"I purposefully didn't make it simpler so people would stop and read and understand: what is AI, that AI can make mistakes, what is prompt injection -- some basics that you really should understand when you use that technology," he told AFP in March.
Whitmore argued that expecting users to create their own guardrails for agents is "pretty unrealistic".
"People are going to adopt innovation and really see what it's capable of before they ask the questions about, 'how do I secure my own data?'," she predicted.
"That's going to cause some significant challenges in terms of data breaches in 2026."
J.AbuShaban--SF-PST