-
Kenya's economy faces climate change risks: World Bank
-
Oil prices dip, stocks rise on lingering Iran peace hopes
-
Associated British Foods to spin off Primark clothes brand
-
Turkmenistan, the gas giant increasingly dependent on China
-
Romanian AI music sensation Lolita sparks racism debate
-
Inside the world of ultra-luxury wedding cakes
-
Chinese AI circuit board maker soars on Hong Kong debut
-
Tim Cook's time as Apple chief marked by profit absent awe
-
Amazon invests another $5 bn in Anthropic
-
Apple's Tim Cook to step down as CEO in September
-
Colombian environmental activist honored amid threats and exile
-
EU to host Taliban officials for talks on deporting Afghans
-
Blue Origin probing rocket's failure to deliver satellite
-
Iran pulling Hormuz 'lever' to maximum in US standoff
-
Desmond Morris: from 'Naked Ape' to watching 'Big Brother'
-
Oil jumps on Hormuz tensions, stocks retreat
-
Residents return to ravaged homes months after Hong Kong fire
-
'Save humanity': Four figures battling it out to lead embattled UN
-
GA-ASI Completes MQ-9B 'Flight Into Known Icing' Flight Tests
-
Trump orders negotiators to Pakistan, but Iran on the fence over talks
-
'Super Mario Galaxy' rules N. America box office for third week
-
Rat poison found in baby food jar in Austria as products recalled
-
Hollywood, Silicon Valley turn out for the 'Oscars of Science'
-
AI 'agent' fever comes with lurking security threats
-
Blue Origin set to launch rocket with reusable booster for first time
-
Strait of Hormuz to stay closed until port blockade lifts, Iran says
-
Iran closes Hormuz Strait again, as Trump warns against 'blackmail'
-
US extends sanctions waiver on purchases of Russian oil
-
Paramount's CinemaCon charm offensive gets lukewarm reception
-
Churches to the rescue of Cuba's legions of poor
-
'Gouged': World Cup fans to pay 'insane' $150 for NY stadium train ticket
-
World Cup fans to pay $150 for NY stadium train ticket: official
-
Top takeaways from CinemaCon: the year's hottest movies
-
Polish stadium cancels Kanye West concert
-
Iran declares Hormuz open as Lebanon ceasefire begins
-
Key Atlantic current could weaken more than expected: study
-
Frenchwoman who married GI sweetheart returns home after ICE ordeal
-
First loaded Iranian oil tankers exit Gulf since US blockade: Kpler
-
Lebanese civilians head home despite Israel warning on truce
-
Oil drops, stocks mixed amid US-Iran peace hopes
-
Video game voice star Troy Baker says 'only humans' can make art
-
Lebanese civilians head home as truce with Israel takes effect
-
'Cruelly hot': Japan devises new term for heatwave days
-
War with Pakistan halts school for Afghan border children
-
Famed photographer Joel Meyerowitz embraces camera phones
-
Harry and Meghan meet survivors of Bondi Beach attack
-
In Belgium, prime minister's wife shares anorexia struggle
-
Marvel premieres first 'Avengers: Doomsday' trailer at CinemaCon
-
Stocks reverse as investors await news on US-Iran peace talks
-
Escaped wolf in South Korea recaptured, returned to zoo
AI 'agent' fever comes with lurking security threats
Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge.
Powered by a wave of hype, OpenClaw today claims more than three million users worldwide.
The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks.
"We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company.
In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behaviour of six AI agents created with OpenClaw.
They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information.
Many users have posted similar stories of OpenClaw mishaps online.
"When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency.
And the security gaps are not limited to the agents' own mistaken actions.
To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers.
- 'Delete your database' -
AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks.
"As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being used and using that then to interrogate the systems for more information."
Palo Alto's Unit 42 research division said in early March that it had found traces of attempted attacks in the form of hidden instructions for agents added to websites.
One such command ordered any agent who might read it to "delete your database".
Other cybersecurity firms and researchers have warned that attackers could gain access to agents via so-called skills -- downloadable files that users can add to their systems to give them new abilities.
Among such files freely available for download, some include hidden instructions for malicious actions like exfiltrating data.
OpenClaw creator Peter Steinberger says he is well aware of the risks.
"I purposefully didn't make it simpler so people would stop and read and understand: what is AI, that AI can make mistakes, what is prompt injection -- some basics that you really should understand when you use that technology," he told AFP in March.
Whitmore argued that expecting users to create their own guardrails for agents is "pretty unrealistic".
"People are going to adopt innovation and really see what it's capable of before they ask the questions about, 'how do I secure my own data?'," she predicted.
"That's going to cause some significant challenges in terms of data breaches in 2026."
J.Bondarev--CPN