-
Seoul says North Korean mines 'highly suspected' as cause of DMZ blast
-
Iran denies link to suspected bomb plot at UK airbase used by US
-
Russia pummels Kyiv in latest deadly daytime attack
-
Ex-boss Mancini says City charges 'not my concern'
-
Wartime Ukraine works to keep its railways on track
-
Berlin Marathon winner Assefa finished race with torn Achilles
-
Boy among 3 dead in migrant Channel crossing accident: French authorities
-
Comedian convicted for Erdogan 'insult' but freed pending appeal
-
SGFX Creates a Standout Brand Experience at Forex Expo Dubai 2026
-
French prosecutors seek two-year sentence for ex-minister Dati in graft case
-
Pope urges Europe to help combat 'deceit and lies' in international ties
-
Eala makes fast start as weather and transport woes hit Asian Games
-
Injured Buttler to miss England ODI series in Pakistan
-
Hurricane Polo approaches Mexico, threatens severe damage
-
Madrid housing protesters vow to maintain pressure on government
-
Energy markets rally after Trump rejects Iran truce offer
-
In kayaks or waist-deep in floodwater, shoppers return to Bangkok markets
-
Japanese convenience store enlists Lady Gaga to bolster recruitment
-
UK police probes Iran link to air base bomb scare: media
-
Seoul summons Ukraine envoy in row over North Korean POWs
-
Eala blasts into Asian Games quarters in just 55 minutes
-
Ireland 'raised awareness worldwide' in Israel game: Hallgrimsson
-
Taiwan gender-row boxer Lin Yu-ting guarantees Asian Games medal
-
Colombian police capture wife, daughter of Ecuador drug lord
-
Comedian on trial for allegedly insulting Erdogan in standup show
-
More Asian Games woes as bus takes Pakistan team to wrong venue
-
More Asian Games transport woes as bus takes Pakistan to wrong venue
-
Radio frequencies vital to Earth observation must be protected: UN
-
Death toll in South Africa bar shooting rises to 18
-
Comedian on trial for insulting Erdogan in standup show
-
Aide to Venezuelan opposition leader returns from exile
-
Women's Fashion Week kicks off in Paris
-
Messi and Alcaraz love it, now padel takes step closer to Olympics
-
Pope arrives in French border city to speak on united Europe
-
Tolls mount in Thailand, Myanmar floods
-
The wildfires choking Indonesia, sparking regional haze
-
Why India's opposition wants top poll official out
-
PU Prime Deepens Argentina Presence Through FX Expo Buenos Aires 2026
-
PU Prime Strengthens UAE Momentum with Strong Showing at Forex Expo Dubai 2026
-
Nothing to seal here: NZ police help stranded pup home
-
Eight dead in Thailand floods since mid-September
-
White House releases list of products US, China could tax less
-
Oil prices spike after Trump rejects Iran truce offer
-
'Pseudo-journalism': Partisan 'news' sites target US midterms
-
Taylor Swift sets new record at MTV VMAs
-
'Currently impossible': North Korea defections in freefall
-
Seoul seeks apology after Ukraine reveals transfer of North Korean POWs
-
Erasmus sizes up 'improved' Wallabies ahead of 2027 World Cup
-
Messi on target again but Miami downed by Columbus
-
Scandal-weary Brazilians to vote as Lula faces Bolsonaro son
'Vibe hacking' puts chatbots to work for cybercriminals
The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.
So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.
The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".
Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".
The attacker has since been banned by Anthropic.
Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.
Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.
Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.
"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.
- Dodging safeguards -
Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.
The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.
But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.
He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.
The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.
"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.
His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.
In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.
Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.
"We're not going to see very sophisticated code created directly by chatbots," he said.
Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.
H.Gerber--VB