-
Iceland votes on whether to resume EU membership talks
-
Heavy gunfire rocks Niger capital, state TV signal cut
-
Rescuers claw through mud as Nepal, China flood missing toll nears 3,000
-
Manchester Airports Group Cyberattack: 8.7 Million Customer Records Exposed
-
CGBio’s Novosis Achieves Bone Union in All Seven Patients in Scaphoid Nonunion Study
-
Nepal floods leave trail of destruction, aid challenge
-
Kinshasa urban train back on track after years to beat gridlock
-
Experts outline sustainable ways to declutter Australian homes
-
Merino crossbreeding plan tests Himachal Pradesh wool ambitions
-
Bulk book purchases feed AI training through destructive scanning
-
Pringles launches thicker Dippers range for US snack market
-
George and Amal Clooney attend Lake Como event after France evacuation
-
US and Venezuela announce 65-billion-barrel oil development agreement
-
Michelle Obama describes relief and adjustment after daughters leave home
-
Assistance-dog dispute puts Great Bernera community groups under financial strain
-
Very strong El Niño forecast to peak during southern African summer
-
Sello Hatang remembers actor Sol Rachilo through a personal archive
-
SAFA opens tender for dressing rooms, ablutions and grandstands
-
UN committee calls on South Africa to dismantle racist vigilante groups
-
TEEKS brings Māori-rooted soul and a new view of masculinity to South Africa
-
South African creators seek stronger businesses beyond brand partnerships
-
Saudi customs seize 1.95 million amphetamine pills in lentil shipment
-
Syria warns Israeli actions could push region toward wider war
-
Trump says Russia will not attack NATO as CIA chief visits Moscow
-
East Midlands Railway warns of bank holiday disruption at St Pancras
-
British Museum schedules new Bayeux Tapestry ticket release
-
Six treated after sign falls at Big Church Festival in West Sussex
-
From forced labour to living heritage: Sao Tome's colonial plantations
-
Norway, in mourning, enters a new era under Haakon VIII
-
Motorola September 2026 Deals: Up to $700 Off Razr Ultra and Moto G
-
Number of missing in Nepal, China floods soars to nearly 3,000
-
In war-split Myanmar 'spirit consorts' commune across divide
-
Number of missing in Nepal, China floods soars past 2,400
-
Leaders of Russia, China, Iran to attend summit in Kyrgyzstan
-
Trump announces deal for huge US stake in Venezuelan oil reserves
-
Hovland and Gerard share lead at Tour Championship
-
Kane confirms talks on Bayern extension
-
Maresca salutes 'unbelievable' Cherki after Man City star sinks Palace
-
Trump govt. mulls deal to give away part of Yosemite park
-
Marquinhos rescues last-gasp draw for PSG at Lille in Ligue 1
-
Indian release of Sonia Gandhi memoir uncertain after publisher clarification
-
ICE detains British far-right activist Milo Yiannopoulos in Louisiana
-
Cities show cleaner transport policies can reduce severe air pollution
-
Milo Yiannopoulos held by ICE after missing immigration hearing
-
Four patients harmed in Nashville hospital medication mix-up
-
Six Flags closes X2 rollercoaster after reports of severe brain injuries
-
Essex council hires private guards as Wethersfield asylum centre expands
-
Jury ends second day without verdict in Lindsay Clancy murder trial
-
Haakon VIII becomes Norway's king after Harald V dies at 89
-
Artist says criticised Ronnie O'Sullivan mural is unfinished
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
T.Ibrahim--SF-PST