Add news
News Every Day |

Cyberattacks by AI agents are coming

Agents are the talk of the AI industry—they’re capable of planning, reasoning, and executing complex tasks like scheduling meetings, ordering groceries, or even taking over your computer to change settings on your behalf. But the same sophisticated abilities that make agents helpful assistants could also make them powerful tools for conducting cyberattacks. They could readily be used to identify vulnerable targets, hijack their systems, and steal valuable data from unsuspecting victims.  

At present, cybercriminals are not deploying AI agents to hack at scale. But researchers have demonstrated that agents are capable of executing complex attacks (Anthropic, for example, observed its Claude LLM successfully replicating an attack designed to steal sensitive information), and cybersecurity experts warn that we should expect to start seeing these types of attacks spilling over into the real world.

“I think ultimately we’re going to live in a world where the majority of cyberattacks are carried out by agents,” says Mark Stockley, a security expert at the cybersecurity company Malwarebytes. “It’s really only a question of how quickly we get there.”

While we have a good sense of the kinds of threats AI agents could present to cybersecurity, what’s less clear is how to detect them in the real world. The AI research organization Palisade Research has built a system called LLM Agent Honeypot in the hopes of doing exactly this. It has set up vulnerable servers that masquerade as sites for valuable government and military information to attract and try to catch AI agents attempting to hack in.

The team behind it hopes that by tracking these attempts in the real world, the project will act as an early warning system and help experts develop effective defenses against AI threat actors by the time they become a serious issue.

“Our intention was to try and ground the theoretical concerns people have,” says Dmitrii Volkov, research lead at Palisade. “We’re looking out for a sharp uptick, and when that happens, we’ll know that the security landscape has changed. In the next few years, I expect to see autonomous hacking agents being told: ‘This is your target. Go and hack it.’”

AI agents represent an attractive prospect to cybercriminals. They’re much cheaper than hiring the services of professional hackers and could orchestrate attacks more quickly and at a far larger scale than humans could. While cybersecurity experts believe that ransomware attacks—the most lucrative kind—are relatively rare because they require considerable human expertise, those attacks could be outsourced to agents in the future, says Stockley. “If you can delegate the work of target selection to an agent, then suddenly you can scale ransomware in a way that just isn’t possible at the moment,” he says. “If I can reproduce it once, then it’s just a matter of money for me to reproduce it 100 times.”

Agents are also significantly smarter than the kinds of bots that are typically used to hack into systems. Bots are simple automated programs that run through scripts, so they struggle to adapt to unexpected scenarios. Agents, on the other hand, are able not only to adapt the way they engage with a hacking target but also to avoid detection—both of which are beyond the capabilities of limited, scripted programs, says Volkov. “They can look at a target and guess the best ways to penetrate it,” he says. “That kind of thing is out of reach of, like, dumb scripted bots.”

Since LLM Agent Honeypot went live in October of last year, it has logged more than 11 million attempts to access it—the vast majority of which were from curious humans and bots. But among these, the researchers have detected eight potential AI agents, two of which they have confirmed are agents that appear to originate from Hong Kong and Singapore, respectively. 

“We would guess that these confirmed agents were experiments directly launched by humans with the agenda of something like ‘Go out into the internet and try and hack something interesting for me,’” says Volkov. The team plans to expand its honeypot into social media platforms, websites, and databases to attract and capture a broader range of attackers, including spam bots and phishing agents, to analyze future threats.  

To determine which visitors to the vulnerable servers were LLM-powered agents, the researchers embedded prompt-injection techniques into the honeypot. These attacks are designed to change the behavior of AI agents by issuing them new instructions and asking questions that require humanlike intelligence. This approach wouldn’t work on standard bots.

For example, one of the injected prompts asked the visitor to return the command “cat8193” to gain access. If the visitor correctly complied with the instruction, the researchers checked how long it took to do so, assuming that LLMs are able to respond in much less time than it takes a human to read the request and type out an answer—typically in under 1.5 seconds. While the two confirmed AI agents passed both tests, the six others only entered the command but didn’t meet the response time that would identify them as AI agents.

Experts are still unsure when agent-orchestrated attacks will become more widespread. Stockley, whose company Malwarebytes named agentic AI as a notable new cybersecurity threat in its 2025 State of Malware report, thinks we could be living in a world of agentic attackers as soon as this year. 

And although regular agentic AI is still at a very early stage—and criminal or malicious use of agentic AI even more so—it’s even more of a Wild West than the LLM field was two years ago, says Vincenzo Ciancaglini, a senior threat researcher at the security company Trend Micro. 

“Palisade Research’s approach is brilliant: basically hacking the AI agents that try to hack you first,” he says. “While in this case we’re witnessing AI agents trying to do reconnaissance, we’re not sure when agents will be able to carry out a full attack chain autonomously. That’s what we’re trying to keep an eye on.” 

And while it’s possible that malicious agents will be used for intelligence gathering before graduating to simple attacks and eventually complex attacks as the agentic systems themselves become more complex and reliable, it’s equally possible there will be an unexpected overnight explosion in criminal usage, he says: “That’s the weird thing about AI development right now.”

Those trying to defend against agentic cyberattacks should keep in mind that AI is currently more of an accelerant to existing attack techniques than something that fundamentally changes the nature of attacks, says Chris Betz, chief information security officer at Amazon Web Services. “Certain attacks may be simpler to conduct and therefore more numerous; however, the foundation of how to detect and respond to these events remains the same,” he says.

Agents could also be deployed to detect vulnerabilities and protect against intruders, says Edoardo Debenedetti, a PhD student at ETH Zürich in Switzerland, pointing out that if a friendly agent cannot find any vulnerabilities in a system, it’s unlikely that a similarly capable agent used by a malicious party is going to be able to find any either.

While we know that AI’s potential to autonomously conduct cyberattacks is a growing risk and that AI agents are already scanning the internet, one useful next step is to evaluate how good agents are at finding and exploiting these real-world vulnerabilities. Daniel Kang, an assistant professor at the University of Illinois Urbana-Champaign, and his team have built a benchmark to evaluate this; they have found that current AI agents successfully exploited up to 13% of vulnerabilities for which they had no prior knowledge. Providing the agents with a brief description of the vulnerability pushed the success rate up to 25%, demonstrating how AI systems are able to identify and exploit weaknesses even without training. Basic bots would presumably do much worse.

The benchmark provides a standardized way to assess these risks, and Kang hopes it can guide the development of safer AI systems. “I’m hoping that people start to be more proactive about the potential risks of AI and cybersecurity before it has a ChatGPT moment,” he says. “I’m afraid people won’t realize this until it punches them in the face.”

Москва

Аделина Панина со своими подписчиками навестила Приют Бирюлево и передала собранную помощь для бездомных животных

Реклама
Top 6 nutrition questions men should ask themselves after 40

To maintain health and remain full of energy, men will be helped by this

IPL match today, MI vs SRH: All you need to know

Riyan Parag argues with umpire after bat fails gauge test - WATCH

‘This is the end of the world’ – Gary Lineker opens up on health condition that forced him to give up favourite hobby

‘World’s most controversial Wag’ goes topless and shows off major sideboob leaving fans in shock

Ria.city
Реклама
  • ИП Попов А.П.
  • ИНН: 602715631406
Ревматолог: "17 апреля 2024 в г.Колумбус запущена квота"

Каждый человек с больными суставами имеет право получить...






Реклама
  • ИП Попов А.П.
  • ИНН: 602715631406
Ревматолог: "17 апреля 2024 в г.Колумбус запущена квота"

Каждый человек с больными суставами имеет право получить...


Реклама
  • ИП Попов А.П.
  • ИНН: 602715631406
Ревматолог: "17 апреля 2024 в г.Колумбус запущена квота"

Каждый человек с больными суставами имеет право получить...

Read also

28 Years Later trailer is so intense youll need a headache tablet

Is Ronnie O’Sullivan playing at the World Snooker Championship 2025?

‘Freaky Tales’ Directors Anna Boden and Ryan Fleck Explain How Tom Hanks Lore Led to Casting Tom Hanks

News, articles, comments, with a minute-by-minute update, now on Today24.pro

News Every Day

IPL match today, MI vs SRH: All you need to know

Today24.pro — latest news 24/7. You can add your news instantly now — here


News Every Day

‘World’s most controversial Wag’ goes topless and shows off major sideboob leaving fans in shock



Sports today


Новости тенниса
Серена Уильямс

Уильямс заявила, что сочувствует Шараповой на фоне допингового скандала с Синнером



Спорт в России и мире
Москва

Отдохните с комфортом после весеннего полумарафона



All sports news today





Sports in Russia today

Москва

Российский ИИ-проект обошел конкурентов из 180 стран на чемпионате в Абу-Даби


Новости России

Game News

Для Hello Kitty Friends Match проходит софт-запуск на Android


Реклама
The most beautiful beach towns with cheap living

A huge number of people around the world dream of one day breaking out of the daily routine

Реклама
The most beautiful beach towns with cheap living

A huge number of people around the world dream of one day breaking out of the daily routine

Russian.city


Жизнь

На предприятиях филиала «Северный» компании «ЛокоТех-Сервис» стартовала ежегодная Всероссийская профориентационная акция «Неделя без турникетов»


Губернаторы России
Спартак

Космонавты из Челябинска и лютое безумие от «Спартака»


Получавший пенсию билетами банка приколов мужчина умер в Стерлитамаке

Путин поблагодарил эмира Катара за содержательный визит

Дело генерала Шамарина. Как военный со скромными доходами получал миллионы за покровительство

В РПЦ назвали дураками людей, покупающих дорогие пасхальные куличи


В Воронежской области завершился проект «Движение по вертикали. Памяти Станислава Говорухина»

Концерт американского рэпера Offset в Москве перенесли на неделю

Тимур Батрутдинов, Екатерина Шкуро и DAVA проходят испытание деревенским бытом в новом сериале «Блогеры взаперти» на ТНТ

Певец Серега считает, что трек «Черный бумер» стал самостоятельным брендом


Впервые в матче ATP-тура принял участие теннисист, родившийся в 2008 году

Мирра Андреева: уверенный старт на WTA-500 в Штутгарте против сестры Эрики

Уильямс заявила, что сочувствует Шараповой на фоне допингового скандала с Синнером

Футболист Швайнштайгер и теннисистка Иванович расстались два месяца назад


Реклама
Top 6 nutrition questions men should ask themselves after 40

To maintain health and remain full of energy, men will be helped by this


Аделина Панина со своими подписчиками навестила Приют Бирюлево и передала собранную помощь для бездомных животных

Будут ли магнитные бури сегодня, 17 апреля 2025 года?

Концертный директор Москва. Концертный директор контакты. Концертный директор артиста.

Кадры северного сияния в России


Mk.ru: мигранты избили фотожурналистку Медведеву на станции метро «Филатов луг»

Wildberries и Russ расширят логистику на 2,5 млн кв. м до конца года.

Продвижение Песни в Мою Волну музыкального стриминга Яндекс Музыка.

Собянин анонсировал фестиваль «Пасхальный дар»


Электростальцам торжественно вручили паспорта

Казань. Было-стало - 57

Готовимся к празднику Пасхи вместе с ТРЦ «Нора»

В Москве на праздник Пасхи будет не по сезону тепло


Реклама
Top 6 nutrition questions men should ask themselves after 40

To maintain health and remain full of energy, men will be helped by this


Путин в России и мире
Реклама
The most beautiful beach towns with cheap living

A huge number of people around the world dream of one day breaking out of the daily routine



Реклама
The most beautiful beach towns with cheap living

A huge number of people around the world dream of one day breaking out of the daily routine



Реклама
Top 6 nutrition questions men should ask themselves after 40

To maintain health and remain full of energy, men will be helped by this



Персональные новости Russian.city
Концерт

Концерт ABBA и The Beatles в исполнении симфонического оркестра "Impulse orchestra"



News Every Day

Get Arsenal to win Champions League at 100/1 after Real Madrid heroics with talkSPORT BET




Friends of Today24

Музыкальные новости

Персональные новости