-
Kenya halts US Ebola facility: health minister tells court
-
Why the heat is wreaking havoc on Europe's trains
-
Zelensky to skip key Ukraine conference in Poland over WWII row
-
Seoul leads rout for tech shares as oil prices dip
-
Europe heatwave closes schools, threatens health
-
India monsoon sweeps north but brings less rain than usual
-
Germany eyes longer working lives in pension reform plan
-
UK and markets await Burnham's economic plans
-
Iran says won't allow UN inspectors at bombed nuclear sites
-
Heineken names new CEO after predecessor's shock departure
-
Banned Vondrousova insists she has 'never doped'
-
Schools plan to close as UK braces for record-breaking heatwave
-
UN chief urges AI firms to 'come clean' over environmental footprint
-
India startup head Kunal Shah appointed as new WhatsApp boss
-
More records set to fall as deadly Europe heatwave drags on
-
Israel's 'deliberate targeting' of children part of ongoing Gaza 'genocide': UN probe
-
England, Ghana eye last 32 as Portugal look for lift-off
-
Seoul's Kospi stock index tanks 10% to lead tech-fuelled Asia rout
-
Sri Lanka troops to battle deadly dengue mosquitoes as cases rise
-
Iran says to oversee Hormuz as Swiss talks conclude
-
Diaspora World Cup champions diversity over division
-
Guns, drones and doves: War reshapes Ukrainian jewellery scene
-
Australia withholds Pacific climate fund reports over risk of diplomatic 'damage'
-
Kenya police violence victims say compensation promise a 'smokescreen'
-
Indian startup head appointed as new WhatsApp boss
-
EU bets on digital euro to cut US tech addiction
-
Antetokounmpo joining Miami Heat in blockbuster: reports
-
Fineanganofo rethinks Newcastle move after All Blacks call-up
-
'Let's be realistic': Haaland cools Norway's World Cup expectations
-
Stocks fluctuate after Wall St sell-off, crude holds losses on peace talks
-
Lightning, downpour, a two-hour delay: bad weather hits the World Cup
-
Ultra-reclusive Turkmenistan slowly opens up to tourists
-
Two-goal Haaland fires Norway into World Cup last 32
-
Marc Bloch, historian and Resistance hero, joins France's Pantheon greats
-
Last one the best one? How Messi keeps doing it at World Cup
-
Ronaldo 'a role model' says Portugal coach after slow World Cup start
-
Savea 'embraces challenge' of leading All Blacks towards World Cup
-
North Korea's Kim vows to accelerate military buildup
-
Savea 'embraces challlenge' of leading All Blacks towards World Cup
-
Latin America's resurgent right notches another win in Colombia
-
Mbappe scores twice as France beat Iraq at World Cup after two-hour storm delay
-
Trump threatens prison for damage to Washington Reflecting Pool
-
France-Iraq World Cup game restarts after two-hour storm delay
-
Shortages ease in Bolivia as protest roadblocks dismantled
-
World Cup exploits of Maradona and Messi have Argentina fans in raptures
-
England 'can beat any opponent' at World Cup, says Rice
-
'Boston Tea Party' compensation claim to be displayed at UK exhibit
-
Alvarez says 'best for everyone' if he leaves Atletico
-
France-Iraq World Cup game suspended due to severe weather alert
-
Romanian parliament rejects liberal PM-designate
'Vibe hacking' puts chatbots to work for cybercriminals
The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.
So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.
The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".
Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".
The attacker has since been banned by Anthropic.
Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.
Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.
Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.
"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.
- Dodging safeguards -
Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.
The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.
But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.
He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.
The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.
"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.
His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.
In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.
Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.
"We're not going to see very sophisticated code created directly by chatbots," he said.
Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.
H.Gerber--VB