-
Vietnamese coffee farmers ride China's durian wave
-
Nepal flood survivors return to ruins to salvage memories
-
Venezuela says retains 'sovereignty' in US oil deal
-
Killing of Palestinian children and teens by Israel surges in West Bank
-
NASA's Roman telescope set to launch on cosmic mapping mission
-
Educators keep 9/11 memory alive for next generation, 25 years on
-
Data center backlash scrambles US midterm politics
-
Venezuelans view US oil deal with doubt, hope
-
Emotional Federer inducted into tennis Hall of Fame
-
Gobena and Jepchirchir power to Sydney Marathon victories
-
Hovland takes solo lead as McIlroy surges at Tour Championship
-
Iceland in suspense after close EU vote
-
Djokovic 'prepared' for US Open bid for history
-
Wallabies hold on for victory in Argentina
-
Atletico down Sevilla to go top of La Liga
-
Juve notch second straight win, Fiorentina's centenary party falls flat
-
US deports right-wing provocateur Milo Yiannopoulos
-
Rybakina eases injury fears ahead of US Open
-
Niger junta says it is back in control after soldiers' mutiny
-
Djokovic kicks off latest Grand Slam quest under US Open lights
-
Erasmus calls Rennie barbs over Springbok scrumming 'nonsense'
-
'Sorry' De Zerbi won't panic after Spurs shambles
-
Lawrence's fifty leaves Pakistan facing record chase to level England series
-
UN, Nepal warn of climate threat after deadly floods
-
Netanyahu condemns settler attack in flashpoint West Bank village
-
USTA boss says structure of new player council not yet set
-
Munoz saves Iraola in Liverpool draw, big-spending Spurs lose again
-
Tiny Elversberg stun Leverkusen on Bundesliga debut, Dortmund beat Hamburg
-
Newcastle condemn dismal Spurs to second successive defeat
-
BMC rejects negligence claims in three Rajawadi Hospital maternity cases
-
Five college football games that could shape the 2026 season
-
Editorial questions Letitia James’ record as New York attorney general
-
New finds strengthen case for Bethsaida at Sea of Galilee site
-
Los Angeles triplets weigh 19.3 pounds in unusually heavy birth
-
Felony assaults on older New Yorkers rise sharply, police data show
-
Matt Leinart assesses Arch Manning and the leading names in college football
-
Three Texas Tech softball players hurt in jet ski collision
-
Rural Tamil Nadu students present 64 technology projects at IIT-M research park
-
Tambaram civic groups seek action on eight long-pending issues
-
Tamil Nadu goalball team’s national silver highlights need for wider support
-
Chennai councillors unite across parties to demand ward development funds
-
Tamil Nadu and NUS agree to expand postgraduate and research links
-
Court orders JIPMER assessment of Durai Dayanidhi before money-laundering trial
-
India and China have not named two new border meeting sites
-
Family searches for Boston engineer missing after Nepal-Tibet floods
-
Ankle ligament tear ends Neeraj Chopra’s 2026 season
-
Dolly Parton’s Imagination Library leaves global children’s reading legacy
-
Thirty-seven Mumbai pilgrims return after Nepal flood disruption
-
Police appeal for footage after life-threatening Stratford assault
-
French campaign sharpens as far right accuses left over civil disobedience calls
'Vibe hacking' puts chatbots to work for cybercriminals
The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.
So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.
The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".
Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".
The attacker has since been banned by Anthropic.
Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.
Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.
Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.
"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.
- Dodging safeguards -
Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.
The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.
But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.
He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.
The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.
"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.
His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.
In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.
Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.
"We're not going to see very sophisticated code created directly by chatbots," he said.
Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.
N.Walker--AT