-
US pauses construction of border project in Texas national park
-
Discord suspends livestreams in Brazil after teen's suicide
-
Thousands mourn dead black academic in London vigil
-
Tupac Shakur's accused killer was out for 'revenge', jury hears
-
South Africa Test series a lot tougher than a World Cup says All Blacks coach Rennie
-
Netanyahu presses role for US general in Hamas disarmament
-
Coventry sign Nigeria striker Awoniyi from Forest
-
US-Palestinian says 'terrified' as he returns to property besieged by settlers
-
TripleDart tops $7 million ARR with AI-led growth, reports 50 per cent EBIT margin
-
Amboss Opens Affiliate Program: Earn Recurring Bitcoin Commissions by Growing Bitcoin Payments
-
Bipartisan backlash as Trump scales back US-South Korea drills
-
Netanyahu, Kushner discuss US general for Hamas disarmament: Israeli official
-
'Never seen one like it': German pensioners flee wildfire
-
Scottish FA withdraws support for FIFA boss Infantino
-
Ipswich sign Enciso and Ouattara in double raid on Strasbourg
-
Belgium fire halts short of German border, but not 'contained'
-
UN laments 'unacceptable' toll of 350 aid workers killed in 2025
-
Number one Shi suffers shock first-round exit at badminton worlds
-
Former child star actress Hayden Panettiere dead at 36
-
Kolisi and Nche may miss South Africa Test against New Zealand
-
Pakistan captain Babar Azam doubtful for England opener
-
Trump threatens Oman: latest developments in US-Iran war
-
Pentagon inks Tomahawk deal amid reports of missile shortfall
-
Stocks lower as Hormuz concerns and high oil prices persist
-
Rain halts India push after Dinusha century lifts Sri Lanka
-
Crowds turn out for 'Total Eclipse' singer Bonnie Tyler's funeral
-
Dinusha hits century as Sri Lanka post 284 in first India Test
-
Mali jails junta-critic broadcaster, influencer for seven years
-
Stocks steady as investors weigh US rate path
-
'Nowhere to run': Indonesian quake survivors plead for help
-
Taiwan's leader says government to propose record defence spending for 2027
-
Belgium fire makes 'limited' spread overnight, more help on way
-
Cambridge head slams 'feeding frenzy' over dead academic
-
Vingegaard brings curtain down on season
-
Ebola outbreak now DR Congo's deadliest ever
-
Dickwella, Dinusha hit fifties as Sri Lanka fight back
-
Germany's coalition split over putting climate in constitution
-
Bangladesh Test cricket reboot delivers in style with historic win
-
Ukraine badminton star: 'How can you feel normal when bombs are falling?'
-
Virgin moves closer to launching Eurostar rival in 2030
-
Rain brings respite as Belgium wrestles massive wildfire
-
Indian marble waste dump becomes unlikely tourist attraction
-
Most stocks rise as US data ease rate fears but fuel economic worries
-
Coach says Australia 'let standards slip' in shock Bangladesh loss
-
India take control of Galle Test as Sri Lanka slump to 99-5
-
Hawaii recovery efforts begin as Lala downgraded, moves west
-
Australia's mushroom murderer appeals conviction
-
Food safety crackdown snares Mumbai's famed restaurants
-
The Nigerian fishing community being eaten up by the Atlantic
-
Trump says US scaling back military drills with Seoul hours before start
AI 'agent' fever comes with lurking security threats
Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge.
Powered by a wave of hype, OpenClaw today claims more than three million users worldwide.
The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks.
"We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company.
In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behaviour of six AI agents created with OpenClaw.
They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information.
Many users have posted similar stories of OpenClaw mishaps online.
"When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency.
And the security gaps are not limited to the agents' own mistaken actions.
To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers.
- 'Delete your database' -
AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks.
"As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being used and using that then to interrogate the systems for more information."
Palo Alto's Unit 42 research division said in early March that it had found traces of attempted attacks in the form of hidden instructions for agents added to websites.
One such command ordered any agent who might read it to "delete your database".
Other cybersecurity firms and researchers have warned that attackers could gain access to agents via so-called skills -- downloadable files that users can add to their systems to give them new abilities.
Among such files freely available for download, some include hidden instructions for malicious actions like exfiltrating data.
OpenClaw creator Peter Steinberger says he is well aware of the risks.
"I purposefully didn't make it simpler so people would stop and read and understand: what is AI, that AI can make mistakes, what is prompt injection -- some basics that you really should understand when you use that technology," he told AFP in March.
Whitmore argued that expecting users to create their own guardrails for agents is "pretty unrealistic".
"People are going to adopt innovation and really see what it's capable of before they ask the questions about, 'how do I secure my own data?'," she predicted.
"That's going to cause some significant challenges in terms of data breaches in 2026."
J.AbuShaban--SF-PST