-
Kenya's economy faces climate change risks: World Bank
-
Vietnam and EU upgrade ties as EU chief visits Hanoi
-
Hongkongers snap up silver as gold becomes 'too expensive'
-
Gold soars past $5,500 as Trump sabre rattles over Iran
-
Samsung logs best-ever profit on AI chip demand
-
China's ambassador warns Australia on buyback of key port
-
As US tensions churn, new generation of protest singers meet the moment
-
Venezuelans eye economic revival with hoped-for oil resurgence
-
Samsung Electronics posts record profit on AI demand
-
French Senate adopts bill to return colonial-era art
-
Tesla profits tumble on lower EV sales, AI spending surge
-
Meta shares jump on strong earnings report
-
Anti-immigration protesters force climbdown in Sundance documentary
-
Springsteen releases fiery ode to Minneapolis shooting victims
-
SpaceX eyes IPO timed to planet alignment and Musk birthday: report
-
Neil Young gifts music to Greenland residents for stress relief
-
Fear in Sicilian town as vast landslide risks widening
-
King Charles III warns world 'going backwards' in climate fight
-
Court orders Dutch to protect Caribbean island from climate change
-
Rules-based trade with US is 'over': Canada central bank head
-
Holocaust survivor urges German MPs to tackle resurgent antisemitism
-
'Extraordinary' trove of ancient species found in China quarry
-
Google unveils AI tool probing mysteries of human genome
-
UK proposes to let websites refuse Google AI search
-
Trump says 'time running out' as Iran threatens tough response
-
Germany cuts growth forecast as recovery slower than hoped
-
Amazon to cut 16,000 jobs worldwide
-
Greenland dispute is 'wake-up call' for Europe: Macron
-
Dollar halts descent, gold keeps climbing before Fed update
-
Sweden plans to ban mobile phones in schools
-
Deutsche Bank offices searched in money laundering probe
-
Susan Sarandon to be honoured at Spain's top film awards
-
Trump says 'time running out' as Iran rejects talks amid 'threats'
-
Spain eyes full service on train tragedy line in 10 days
-
Greenland dispute 'strategic wake-up call for all of Europe,' says Macron
-
SKorean chip giant SK hynix posts record operating profit for 2025
-
Greenland's elite dogsled unit patrols desolate, icy Arctic
-
Uganda's Quidditch players with global dreams
-
'Hard to survive': Kyiv's elderly shiver after Russian attacks on power and heat
-
Polish migrants return home to a changed country
-
Dutch tech giant ASML posts bumper profits, eyes bright AI future
-
Minnesota congresswoman unbowed after attacked with liquid
-
Backlash as Australia kills dingoes after backpacker death
-
Omar attacked in Minneapolis after Trump vows to 'de-escalate'
-
Dollar struggles to recover from losses after Trump comments
-
Greenland blues to Delhi red carpet: EU finds solace in India
-
French ex-senator found guilty of drugging lawmaker
-
US Fed set to pause rate cuts as it defies Trump pressure
-
Trump says will 'de-escalate' in Minneapolis after shooting backlash
-
CERN chief upbeat on funding for new particle collider
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
H.Müller--CPN