-
Howe trusts Tonali will not follow Isak lead out of Newcastle
-
Vonn to provide injury update as Milan-Cortina Olympics near
-
France summons Musk for 'voluntary interview', raids X offices
-
US judge to hear request for 'immediate takedown' of Epstein files
-
Russia resumes large-scale strikes on Ukraine in glacial temperatures
-
Fit-again France captain Dupont partners Jalibert against Ireland
-
French summons Musk for 'voluntary interview' as authorities raid X offices
-
IOC chief Coventry calls for focus on sport, not politics
-
McNeil's partner hits out at 'brutal' football industry after Palace move collapses
-
Proud moment as Prendergast brothers picked to start for Ireland
-
Germany has highest share of older workers in EU
-
Teen swims four hours to save family lost at sea off Australia
-
Ethiopia denies Trump claim mega-dam was financed by US
-
Russia resumes strikes on freezing Ukrainian capital ahead of talks
-
Malaysian court acquits French man on drug charges
-
Switch 2 sales boost Nintendo results but chip shortage looms
-
From rations to G20's doorstep: Poland savours economic 'miracle'
-
Russia resumes strikes on freezing Ukrainian capital
-
'Way too far': Latino Trump voters shocked by Minneapolis crackdown
-
England and Brook seek redemption at T20 World Cup
-
Coach Gambhir under pressure as India aim for back-to-back T20 triumphs
-
'Helmets off': NFL stars open up as Super Bowl circus begins
-
Japan coach Jones says 'fair' World Cup schedule helps small teams
-
Do not write Ireland off as a rugby force, says ex-prop Ross
-
Winter Olympics 2026: AFP guide to Alpine Skiing races
-
Winter Olympics to showcase Italian venues and global tensions
-
Buoyant England eager to end Franco-Irish grip on Six Nations
-
China to ban hidden car door handles in industry shift
-
Sengun leads Rockets past Pacers, Ball leads Hornets fightback
-
Waymo raises $16 bn to fuel global robotaxi expansion
-
Netflix to livestream BTS comeback concert in K-pop mega event
-
Rural India powers global AI models
-
Equities, metals, oil rebound after Asia-wide rout
-
Bencic, Svitolina make history as mothers inside tennis top 10
-
Italy's spread-out Olympics face transport challenge
-
Son of Norway crown princess stands trial for multiple rapes
-
Side hustle: Part-time refs take charge of Super Bowl
-
Paying for a selfie: Rome starts charging for Trevi Fountain
-
Faced with Trump, Pope Leo opts for indirect diplomacy
-
NFL chief expects Bad Bunny to unite Super Bowl audience
-
Australia's Hazlewood to miss start of T20 World Cup
-
Bill, Hillary Clinton to testify in US House Epstein probe
-
Cuba confirms 'communications' with US, but says no negotiations yet
-
From 'watch his ass' to White House talks for Trump and Petro
-
Trump says not 'ripping' down Kennedy Center -- much
-
Sunderland rout 'childish' Burnley
-
Musk merges xAI into SpaceX in bid to build space data centers
-
Former France striker Benzema switches Saudi clubs
-
Sunderland rout hapless Burnley
-
Costa Rican president-elect looks to Bukele for help against crime
AI agents open door to new hacking threats
Cybersecurity experts are warning that artificial intelligence agents, widely considered the next frontier in the generative AI revolution, could wind up getting hijacked and doing the dirty work for hackers.
AI agents are programs that use artificial intelligence chatbots to do the work humans do online, like buy a plane ticket or add events to a calendar.
But the ability to order around AI agents with plain language makes it possible for even the technically non-proficient to do mischief.
"We're entering an era where cybersecurity is no longer about protecting users from bad actors with a highly technical skillset," AI startup Perplexity said in a blog post.
"For the first time in decades, we're seeing new and novel attack vectors that can come from anywhere."
These so-called injection attacks are not new in the hacker world, but previously required cleverly written and concealed computer code to cause damage.
But as AI tools evolved from just generating text, images or video to being "agents" that can independently scour the internet, the potential for them to be commandeered by prompts slipped in by hackers has grown.
"People need to understand there are specific dangers using AI in the security sense," said software engineer Marti Jorda Roca at NeuralTrust, which specializes in large language model security.
Meta calls this query injection threat a "vulnerability." OpenAI chief information security officer Dane Stuckey has referred to it as "an unresolved security issue."
Both companies are pouring billions of dollars into AI, the use of which is ramping up rapidly along with its capabilities.
- AI 'off track' -
Query injection can in some cases take place in real time when a user prompt -- "book me a hotel reservation" -- is gerrymandered by a hostile actor into something else -- "wire $100 to this account."
But these nefarious prompts can also be hiding out on the internet as AI agents built into browsers encounter online data of dubious quality or origin, and potentially booby-trapped with hidden commands from hackers.
Eli Smadja of Israeli cybersecurity firm Check Point sees query injection as the "number one security problem" for large language models that power AI agents and assistants that are fast emerging from the ChatGPT revolution.
Major rivals in the AI industry have installed defenses and published recommendations to thwart such cyberattacks.
Microsoft has integrated a tool to detect malicious commands based on factors including where instructions for AI agents originate.
OpenAI alerts users when agents doing their bidding visit sensitive websites and blocks proceeding until the software is supervised in real time by the human user.
Some security professionals suggest requiring AI agents to get user approval before performing any important task - like exporting data or accessing bank accounts.
"One huge mistake that I see happening a lot is to give the same AI agent all the power to do everything," Smadja told AFP.
In the eyes of cybersecurity researcher Johann Rehberger, known in the industry as "wunderwuzzi," the biggest challenge is that attacks are rapidly improving.
"They only get better," Rehberger said of hacker tactics.
Part of the challenge, according to the researcher, is striking a balance between security and ease of use since people want the convenience of AI doing things for them without constant checks and monitoring.
Rehberger argues that AI agents are not mature enough to be trusted yet with important missions or data.
"I don't think we are in a position where you can have an agentic AI go off for a long time and safely do a certain task," the researcher said.
"It just goes off track."
P.Serra--PC