-
Candidate for UN chief calls for AI regulation akin to nuclear weapons
-
US Fed raises rates to battle inflation in move likely to rile Trump
-
'We're losing control,' AI pioneer Yoshua Bengio tells AFP
-
US House faces test on sweeping Russia sanctions bill
-
IR-MED and Dice Technologies Announce collaboration to Evaluate and Advance Pressure-Injury Prevention Platform in Japan
-
British PM says to make 'difficult decisions' as inflation rises
-
Watts, Pitt, Cruz to light up Spain's top film festival
-
Global fuel price demos: a round-up
-
Toogood Gold's Table Mountain Sits in the Shadow of a Nevada Gold Rush
-
Leverate Launches MCP for Traders to Connect AI Assistants With Trading Platforms
-
MEXC July–August Security Report: 38.66M USDT in Risk Funds Intercepted, Futures Insurance Fund Hits 792M USDT
-
MEXC Launches $1M "Discover Your Wall Street DNA" Campaign to Help Traders Find Their Market Fit
-
Emporio Armani names Dario Vitale new creative director
-
Stocks edge higher ahead of US Fed rate call
-
EU to ban social media for under 13s, curb access until 15
-
BASIS.pro Expands On-Chain Infrastructure with XDC Network Partnership and Zypher DAO as Auto Earn Goes Live
-
Wildfires push endangered Sumatran elephants to brink: Indonesian NGO
-
Pickle-flavoured tart? AI inspires Japan's convenience stores
-
Bank of Japan set to raise rates under pressure from inflation, US
-
EU chief hosts Canada's Carney in push to 'deepen' alliance
-
EU chief to unveil social media, gaming curbs for under-15s
-
Meta chief pushes back on AI slowdown calls
-
'Resident Evil' film brings video game's ethos to the big screen
-
US Fed to deliver rate decision with markets betting on hike
-
GA-ASI Mojave First UAS To Complete Battlefield Short Field Ops
-
i-payout Expands U.S. Money Transmitter Licensing Footprint and Advances European EMI Strategy
-
Sanders, Bannon warn of AI dangers in rare US left-right alignment
-
US Senate crypto bill collapses amid partisan deadlock
-
Empty benches as schools reopen in Venezuela's quake-hit Guaira
-
OpenAI, Anthropic and Google are working to create an AI standards body
-
Tiny English village holds 'independence' vote over asylum seeker housing
-
Protesting shepherds, farmers clash with Romanian police
-
US Treasury chief says to meet Chinese counterpart at weekend
-
Foundation Lets Ledger Users Switch to Open Source Without Starting Over
-
BingX Evolves into a Multi-Asset Trading Platform, Connecting Users to Global Opportunities
-
EU to propose curbing social media, online games for under 15s
-
International Trading Institute Expands Professional Trader Development Beyond the Master’s in Trading
-
FX Junction Reaches 40,600 Members and 26 Million Trades
-
Lake Energy Secures $80 Million for U.S. Renewable Energy Expansion
-
'We unleashed the beast': the world's fears and hopes about AI
-
Stocks drop, oil climbs and Treasury yields hit 19-year high
-
Hospitality leaders ask Burnham to halve VAT amid rising costs
-
SkySail Strategies Outperforms Wall Street's 30-Year Risk Standard With Proprietary AI Inference Model
-
Worcestershire invited to nominate groups for 2027 King’s volunteer award
-
Just add fish: Scientists pursue more rice, less disease in Senegal paddies
-
Berlin's run-down public spaces at heart of election campaign
-
Belgium completes outer structure of offshore energy island
-
'Widow's Bay' and 'The Pitt' win big at Emmy Awards
-
China retail sales growth weakens further in August
-
Most markets drop as oil extends gains ahead of expected US rate hike
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
H.Müller--CPN