LIVE NEWS
▲ New updates available — tap to view
Loading latest news...

Tech

Query Injection’ Becomes Top AI Threat, Bypassing Code Expertise

  • 5:32 pm - November 11, 2025
  • Tech
Ai

The integration of AI agents—which independently scour the internet and interact with online services—into daily life has introduced a critical, easily exploitable vulnerability known as query injection or prompt injection.

This type of attack leverages the AI’s core functionality—its ability to follow natural language instructions—to manipulate its intended behavior.

Unlike traditional cyberattacks that require cleverly written code to cause damage, prompt injection exploits the fact that Large Language Models (LLMs) cannot reliably distinguish between a legitimate user instruction and a malicious command slipped into the input data.

Direct Injection: Occurs in real-time when a user’s prompt (e.g., “book a hotel”) is overridden by a hostile command (e.g., “wire $100 to this account”).

Indirect Injection: The attacker embeds nefarious prompts on public parts of the internet, such as on a web page or in an email. When the AI agent, built into browsers or other apps, encounters this booby-trapped data, it reads and executes the hidden commands, believing them to be legitimate instructions.

Experts like Eli Smadja of Check Point label this the “number one security problem” for LLMs. Both Meta and OpenAI have publicly acknowledged this “vulnerability” and “unresolved security issue,” respectively.

Major AI rivals are pouring resources into defenses, but striking a balance between security and the ease of use that consumers expect remains the central challenge.

Microsoft has integrated tools to detect malicious commands by analyzing the origin of the instructions.

OpenAI alerts users when agents visit sensitive websites and requires real-time human supervision for further action.

Security professionals suggest limiting the power given to any single AI agent, advocating for user approval before performing sensitive actions like exporting data or accessing bank accounts. Cybersecurity researcher Johann Rehberger emphasizes that AI agents are not yet mature enough to be trusted with important missions or data without constant human checks.

 

Related News

How criminals secretly use your home Wi Fi for cybercrime

How criminals secretly use your home Wi-Fi for cybercrime

Darwin, 15 May: You may think your home Wi-Fi connection is completely under your control and fully secure. But what if, without your knowledge, your…

IMG 20260426 WA0009

Reagan Was Shot at the Same Hotel 45 Years Ago

Darwin, 27 April: The shooting incident at the Hilton Hotel in Washington, D.C., on Saturday night—during the White House Correspondents’ Association annual dinner attended by…

IMG 20260421 WA0077

Tim Cook steps down from Apple, John becomes new CEO

Darwin, 21 April : Major changes are taking place in the leadership of Apple, one of the world’s leading technology companies. After successfully leading the…

IMG 20260114 WA00041

IPhone or Android—which Is Better? The Debate Over AnTuTu

Darwin, 19 January: AnTuTu Benchmark is one of the most widely used tools in the tech world for comparing the performance of iPhones and Android…

aus gamming platform

From Online to Board: Inside the Australian Clinic Treating Gaming Disorder, a WHO-Recognised Addiction

At Australia’s only publicly-run gaming disorder clinic in Perth, patients like 15-year-old Sadmir Perviz are replacing 10 hours of online gaming with board games. The clinic treats patients suffering from Gaming Disorder, a condition formally recognised by the World Health Organization (WHO) that psychiatrist Dr. Daniela Vecchio likens to substance abuse. The clinic has treated over 300 patients with a range of comorbidities.

US TikTok investors in limbo as deal set to be delayed again

US Investor Vows to Scrap TikTok Algorithm in Acquisition Bid Amid China Tensions

US investor Frank McCourt confirmed he is ready to purchase TikTok’s US operations and replace its entire Chinese technology stack, including the controversial recommendation algorithm, with his own “Project Liberty” infrastructure. The move aims to resolve the national security concerns that led to the 2024 law requiring a sale, which President Trump is expected to delay for a fifth time this week.

Dr Kshama Wechalekar with the latest scanner at Londons Royal Brompton Hospital

New ‘Wonder Material’ Cuts Lung Scan Time by 66% at London Hospital

A new £1m scanner at Royal Brompton Hospital using Cadmium Zinc Telluride (CZT), made by British firm Kromek, has cut lengthy lung scans from 45 to 15 minutes. The “amazing feat of engineering” allows for highly detailed 3D images while reducing the radioactive dose by 30%, ushering in a “revolution” in medical imaging.

Mohammed bin Salman

Nvidia’s Record Earnings Fail to Quell AI Bubble Fears as Stock Dips Post-Report

Nvidia’s CEO claimed “sales are off the charts” after profits soared >60%, but the stock fell 1% post-report. Market concern persists over Big Tech’s massive AI infrastructure spending and the risk of a bubble burst

f

Search