-
Chinese suppliers, Mideast importers fret about war fallout on trade
-
Markets steadier on Mideast peace hopes, as war hits luxury goods
-
EU says age-check app 'ready' in push to protect children online
-
New Hungarian leader Magyar says pro-Orban president must resign
-
After three years of war, Sudan confronts devastation as donors gather in Berlin
-
Pope heads to Cameroon with message of peace for conflict zone
-
OpenAI announces restricted-access cybersecurity model
-
England's Stokes 'quite lucky' to be alive after facial injury
-
Keiko Fujimori: Peru's biggest political loser inches toward victory
-
Barcelona hope young talent learn from Champions League disappointment
-
The Middle East war: latest developments
-
French luxury firms Hermes, Kering knocked by disappointing sales
-
Ukraine veteran stages puppet shows to honour killed soldiers
-
Afghans comb riverbed in search of gold dust
-
Stocks rally, oil falls further as Trump fans fresh peace hopes
-
Double Olympic badminton champion Axelsen announces retirement
-
Peru candidate demands vote annulment as count tightens
-
Tom Cruise shares sneak peek of Inarritu comedy 'Digger' at CinemaCon
-
Rosalia caps journey from student to star with Barcelona concerts
-
AI expansion drives up profits at bullish tech giant ASML
-
Hamano strikes as Japan end US winning streak
-
Xi meets Russian FM as leaders flock to China over Middle East war
-
'Industrial' clickbait disinformation targets Australian politics
-
AI-driven chip shortage slowing efforts to get world online: GSMA
-
Ball hero and villain as Hornets sting Heat, Blazers eclipse Suns
-
Kanye West postpones France concert after minister's block call
-
Indonesia, France agree to boost defence industry ties
-
Super Rugby's Moana Pasifika to fold over financial problems
-
Ball hero and villain as Hornets sting Heat to lift NBA postseason curse
-
Capcom looks to extend 'golden age' with sci-fi action game 'Pragmata'
-
Stocks rally, oil extends losses as Trump fans fresh peace hopes
-
Pope to urge peace in Cameroon's conflict zone
-
US lawmaker demands FIFA pay World Cup transport bill amid ticket hikes
-
World Cup 2026: Haiti, a ravaged nation whose heart beats for football
-
'Listening bars' bloom as hottest new nightlife trend
-
Cinema owners welcome back an old friend as Godzilla sequel unveiled
-
Peru candidate calls for vote annulment as count tightens
-
Trump says Iran talks may resume as Israel, Lebanon open direct track
-
Ekitike injury 'looks really bad', says concerned Slot
-
Atletico 'ready' for Champions League success at last: Simeone
-
Slot in the firing line as Liverpool blown away by PSG
-
Barcelona deserved to go through but must learn from KO: Flick
-
Konate fumes over Liverpool's rejected penalty in PSG defeat
-
Dembele hails PSG's ability to 'suffer' in win over Liverpool
-
Atletico resist Barca comeback to reach Champions League semis
-
Netflix boss Sarandos has 'constructive' talks with cinema owners
-
Atletico resist Barca to reach Champions League semis
-
Dembele sends PSG past wounded Liverpool into Champions League semis
-
England beat Spain in Women's World Cup qualifier
-
Pope walks in Augustine's footsteps as Algeria trip draws to an end
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
T.Ibrahim--SF-PST