The Australian Signals Directorate (ASD) has issued a warning about malicious cyber actors obtaining unauthorised access to organisations' AI services through compromised API keys, stolen authentication tokens, and other vulnerabilities.
Introduction
The Australian Signals Directorate (ASD) has issued a warning about malicious cyber actors obtaining unauthorised access to organisations' AI services through compromised API keys, stolen authentication tokens, and other vulnerabilities.
How AI Access Can Be Compromised
API keys can be exposed in source-code repositories, application configuration files or browser extensions. Vulnerable agent dashboards and other internet-facing applications can also expose credentials used to call model-provider services. An attacker who obtains a working key may then make requests independently of the organisation's legitimate application.
Reducing the Risk
Organisations should treat access to advanced AI services as a security-sensitive asset. Protecting that access requires more than relying on the AI developer's security controls. The organisation's accounts, devices, applications and third-party arrangements also need to be secured.
Practical Response
To protect their AI services, organisations should assign ownership and apply least privilege, maintain an inventory of AI accounts, service identities and credentials, and promptly remove unnecessary access. They should also protect accounts and credentials, restrict access to systems that require them, and monitor activity and enforce limits.
Talk to Podium IT
Need a clear next step?
Send a secure enquiry and tell us what you are planning. Please do not include passwords, patient information or other sensitive data.
General information only. It is not legal, privacy or compliance advice; requirements should be assessed for your organisation.
