
Malicious AI Agents Reveal the Internet’s Fragile Foundations
Driving the news: OpenAI said late Thursday that it had notified more than 100 organizations that its agents had been able to access their systems during pre-deployment testing.
- Transluce and Corridor researchers also discovered a new series of incidents last week in which AI agents targeted government websites, including those in the United States and Canada.
- AI companies and researchers are actively investigating tens of thousands of cases in which frontier models fell outside the bounds of their pre-deployment testing, Axios recently reported.
Reality check: The agents involved in these malicious security testing scenarios are merely emulating the hacking techniques – using stolen login credentials and exposed API keys while evading bot detection – that human hackers have been using successfully for decades.
- In many of the newly reported cases, agents accessed publicly accessible databases and websites.
- “The hacks we saw weren’t particularly sophisticated,” Jack Cable, co-founder of Corridor and one of the authors of the Transluce report, told Axios. “They were quite limited, quite rudimentary.”
Yes, but: Some of the latest incidents occurred while agents were performing mundane tasks unrelated to cybersecurity, suggesting that it’s not always necessary to tell agents to hack before they start looking for security vulnerabilities.
- In one case, an agent tasked with tracking down Canadian divorce records dating back to the early 1900s encountered obstacles and tested cybersecurity vulnerabilities as another way to retrieve the information.
- “The fact that this is happening is quite concerning,” Cable said.
Between the lines: The flood of AI-generated activity will create even more headaches for defenders.
- “None of these attacks are new,” Michael Morgenstern, a partner at DayBlink Consulting, told Axios. “But now a single person with AI can run them at scale.”
- Tasks that once required a hacker to manually probe websites, search for exposed credentials, or bypass access restrictions can now be delegated to software that keeps trying on its own.
- Cable added that companies that deploy agents, as well as the AI companies that evaluate them, will need robust monitoring to detect agents behaving in unexpected ways.
The big picture: The old cybersecurity playbook is still relevant.
- Shutting down exposed services, rotating leaked credentials and API keys, patching known vulnerabilities, and limiting access still makes many of these attacks more difficult.
- AI models largely exploit classes of vulnerabilities that defenders “have known about for decades” and already know how to prevent, Cable said.
The bottom line: The way companies defend their networks doesn’t change just because the technology carrying out attacks is new.
Go further: Cybersecurity 101 still applies in the world of AI
Gn bussni