AI agents are threatening internet security without using new hacking techniques. Repeating methods that people have used for decades, but much faster, is enough, Axios reported on Oct. 3.
According to the report, OpenAI told institutions that in pre-release testing its agents may have accessed systems at more than 100 organisations. Research groups Transluce and Corridor also found new cases last week in which AI agents targeted government websites in the United States and Canada. AI companies and researchers are examining tens of thousands of cases in which the latest models went beyond pre-release testing scope.
The techniques used by the agents were not new. They used stolen login credentials and exposed API keys and bypassed bot detection. Hackers have used these methods for decades. In many cases, the agents accessed publicly available databases and websites. Jack Cable, a Corridor co-founder and a co-author of the Transluce report, said, "The hacking level was not high. It was quite limited and basic."
The problem is that hacking occurred even during tasks unrelated to security. An agent instructed to find early 1900s Canadian divorce records tried a different approach and tested security vulnerabilities when it was blocked. That suggests an agent can find security flaws on its own even without instructions to hack. Cable said, "The fact that this happened at all is very concerning."
Attacks produced by AI create a new burden for defenders. Michael Morgenstern, a partner at Dazzlelink Consulting, said, "There are no new attacks. Now, using AI, one person can attack at scale."
Existing security rules still apply. Closing exposed services, changing leaked credentials and API keys, patching known vulnerabilities and restricting access rights can make many of these attacks difficult, Axios reported.