-
New space object 'black hole star' discovered by astronomers
-
Grieving Argentine icon Messi unsure about playing on 'much longer'
-
England captain Root tells players to be 'adults' as he ditches curfew
-
Nigeria kidnap victims escape 'hellfire' captivity beaten, malnourished
-
US inflation slows slightly in July despite elevated fuel prices
-
Google unveils finder tag, new AI smartphone features
-
Total solar eclipse to cast its shadow over Europe
-
US equities gain as inflation report eases fear of rate rise
-
US consumer inflation slows slightly in July despite elevated fuel prices
-
Colombia declares three days mourning for quake victims
-
Warholm on track in bid for fourth Euro hurdles gold
-
44 lives lost after ferry capsizes on Zimbabwe's Lake Kariba
-
Erdogan eyes expansion of regional defence pact
-
WallStreetPR Releases Report on China’s Gold Purchases and African Mining Investment
-
Extreme weather, jellyfish knock one-fifth of France's nuclear capacity offline
-
Former Chinese premier Zhu Rongji dies aged 97
-
Skywatchers gather in Europe to see total solar eclipse
-
Markets steady awaiting US inflation data
-
Zhu Rongji, trailblazing ex-premier who transformed China's economy
-
WHO says Trump vaccine shake-up goes against evidence
-
China tech giant Tencent's Q2 profit down as AI push builds
-
Eclipse chasers flock to Spain for 'breathtaking' experience
-
China's C919 jet makes first international commercial flight
-
'To make the civilians leave': Russia pummels Ukraine's petrol stations
-
Mideast war impact on travel bookings fading, TUI says
-
Japan brushes off Australian PM's melon drama
-
Bangladesh get Das fitness boost for daunting Australia task
-
Rod Stewart cancels tour dates after heart surgery
-
One dead, 172 rescued as second ferry in days catches fire in Indonesia
-
How Britain's mapmakers track climate change
-
Foxconn posts quarterly profit surge on AI server demand
-
Australian delivery drivers win 'world-leading' pay rise
-
Hazlewood gets Australia nod ahead of Boland for Bangladesh Test
-
Meta meets its own 'tobacco' moment in court
-
Toyota ex-chief Okuda, pioneer of the Prius, dead at 93
-
Art or medicine? Japan's cosmetic tattoo artists in limbo
-
Colombia rescuers find woman alive as quake death toll passes 200
-
Rybakina ousts Osaka to book Toronto semi-final against Gauff
-
New Zealand PM survives leadership challenge months from election
-
Colombia rescuers find woman alive as quake death toll passes 240
-
Passengers rescued as second ferry in days catches fire in Indonesia
-
Charges dropped against Bondi Beach attack hero
-
Oil prices rise, stocks mixed ahead of crucial US inflation data
-
Parched and desperate for rain, Kazakhstan turns to cloud-seeding
-
UK 'joke' candidate Binface pushes serious point about politics
-
The perfect storm that turbocharged Venezuela's twin quakes
-
New Zealand PM Luxon survives leadership challenge months from election
-
2.4 million girls banned from Afghan schools since Taliban return: UNESCO
-
Cuba celebrates Castro's 100th as his revolution faces its toughest test
-
Colombians dig through rubble as quake death toll surpasses 240
'Vibe hacking' puts chatbots to work for cybercriminals
The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.
So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.
The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".
Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".
The attacker has since been banned by Anthropic.
Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.
Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.
Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.
"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.
- Dodging safeguards -
Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.
The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.
But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.
He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.
The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.
"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.
His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.
In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.
Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.
"We're not going to see very sophisticated code created directly by chatbots," he said.
Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.
T.Resende--PC