-
Rams survive Panthers scare to advance in NFL playoffs
-
Rallies across US after woman shot and killed by immigration agent
-
Egypt dump out holders Ivory Coast as Nigeria set up AFCON semi with Morocco
-
Rosenior salutes 'outstanding' start to Chelsea reign
-
Maduro loyalists stage modest rally as Venezuelan govt courts US
-
Byrne late penalty fires Leinster into Champions Cup last 16 after 'ding-dong' battle
-
Rosenior makes flying start as Chelsea rout Charlton in FA Cup
-
Rallies across US against shooting of woman by immigration agent
-
Salah closer to AFCON glory as Egypt dethrone champions Ivory Coast
-
O'Neil ends 'crazy three days' with Strasbourg cup canter
-
Mitchell leads Cavs over T-Wolves
-
O'Neil ends 'crazy few days' with Strasbourg cup canter
-
Argentina wildfire burns over 5,500 hectares: governor
-
Byrne late penalty fires Leinster into Champions Cup last 16
-
Roma beat Sassuolo to close in on Serie A leaders Inter
-
Villa's FA Cup win at Spurs leaves Frank on the brink
-
Osimhen focused on Nigeria glory not scoring record
-
Undav calls shots as Stuttgart thump Leverkusen
-
Venezuelan prisoners smile to hear of Maduro's fall
-
Thousands of Irish, French farmers protest EU-Mercosur trade deal
-
Kiplimo captures third straight world cross country title
-
Osimhen leads Nigeria past Algeria into AFCON semi-finals
-
US urges fresh talks between Syria govt, Kurds after deadly clashes
-
Weekend of US protests after woman killed by immigration agent
-
Monaco cling on with 10 men to avoid French Cup shock
-
Rooney close to tears as brother masterminds FA Cup history
-
Semenyo scores on Man City debut in 10-goal rout of Exeter
-
Villarreal sink Alaves to stay in La Liga hunt
-
Bristol, Glasgow reach Champions Cup last 16
-
Freiburg beat 10-man Hamburg to climb to eighth in the Bundesliga
-
Venezuela loyalists to rally one week after Maduro's capture
-
Syrian authorities transferring Kurdish fighters from Aleppo to northeast
-
Football: Five memorable FA Cup upsets
-
Odermatt warms up for Winter Games with Adelboden giant slalom win
-
Benin showcases culture with Vodun Days
-
Iran crackdown fears grow as protests persist
-
Odermatt wins Adelboden giant slalom for sixth World Cup success of season
-
Holders Crystal Palace stunned by Macclesfield in biggest ever FA Cup shock
-
Odermatt wins Abelboden giant slalom for sixth World Cup success of season
-
Poland reach United Cup final despite Swiatek loss to Gauff
-
India's Gill calls it 'destiny' after shock T20 World Cup snub
-
'Driven' Vonn storms to 84th World Cup win in Austrian downhill
-
Syrian army says stopping Aleppo operations, but Kurds deny fighting over
-
Thousands of Irish farmers protest EU-Mercosur trade deal
-
Vonn storms to 84th World Cup win in Austrian downhill
-
Anger over fatal Minneapolis shooting fuels US protests
-
New rallies erupt in Iran as crackdown fears grow
-
Real Madrid not 'kamikaze' with Mbappe health: Alonso
-
South Africa defends naval drills with Iran, Russia as 'essential'
-
Alcaraz beats Sinner in sold-out South Korea exhibition match
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
T.Ibrahim--SF-PST