-
Anthropic bans 'cruel' behavior against its Claude AI
-
US military to livestream firing squad execution of Fort Hood shooter
-
Anne Carson's Nobel literature prize 'a proud moment for Canada': PM
-
Aces star Wilson wins record-extending fifth WNBA MVP
-
Montagliani to seek CONCACAF re-election in boost for Infantino: reports
-
Undefeated 49ers seek Seahawks revenge
-
Oil surges, stocks sink on jitters over US plans in Iran war
-
Madrid mourns evicted retiree, 'icon' of Spain housing protests
-
John Cena and Jessica Biel hit the gas in 'Matchbox: The Movie'
-
OpenAI revenue gap report rattles AI stocks
-
US, Ukrainians, Europeans to discuss 'new ideas' to end war
-
France pledges more teachers after school students vow no let-up
-
Unproven 'cures' pushed online amid plague concerns
-
Bordeaux confirmed in sixth tier of French football
-
Nigeria looks to ease fuel prices as election looms
-
Trump gives 'national treasure' Musk top US medal after rift
-
Prosecutors in Maradona death trial seek sentences up to 12 years
-
MLB proposes shortening season, reforming playoffs
-
Swiss captain Xhaka gets suspended fine for fake Covid cert
-
Crew splashes down after 8-month mission on International Space Station
-
Ex-prince Andrew raid warrants ruled 'unlawful' but UK police maintain probe
-
Protests, clashes as S. African anti-migrant tensions reignite
-
Two Latvians arrested inside UK military base: police
-
Russian data centre hit by drone in first for Ukraine war
-
Eckert 'forever grateful' for Southampton support over spy scandal
-
'Fighting for our future': France high school students vow no let-up
-
Venezuela's Maduro, wife hit with new US torture charges
-
Kyiv entering 'survival' mode amid Russian strikes surge: mayor tells AFP
-
Argentina friendlies no fairy tale for African footballers
-
Verdict due in Mexico trial over murders of Australia, US surfers
-
US suspending Microsoft from visa program: Vance
-
B2PRIME Welcomes Christina Barbash as Commercial Manager
-
Man City must 'stick together' during crisis, says Haaland
-
Russia forcing Kyiv into 'survival' mode before winter, mayor tells AFP
-
CAS opens hearing into Senegal AFCON title appeal
-
Closing arguments begin in Maradona death trial
-
UK police agree searches for ex-prince Andrew's homes 'unlawful': judge
-
UEFA president Ceferin to stand for re-election in 2027
-
After botched US execution, Christa Pike walking, mentally 'foggy': lawyer
-
Nearly 300,000 Nepalis at flood risk: study
-
'Stunned' Madrid mourns pensioner who sparked housing protests
-
Riyadh kindergarten hit by interception debris as Houthis say targeted airport
-
High school students turn out for new protests across France
-
Alex Bodi mizează, alături de CRIF, pe investiții transparente și pe prevenirea riguroasă a spălării banilor
-
Bid by Italy's Intesa bank to take over MPS gets boost
-
Gulf Labs, Part of Thailand’s $27 Billion GULF Group, Goes Live as an Injective Validator
-
Stablecoins Are Quietly Becoming Business Infrastructure, NOWPayments Data Shows
-
EU okay for winter despite 'historically low' gas stocks: operators
-
Oil surges, stocks sink as US reportedly eyes new Iran strikes
-
Rwanda to host F1 Grand Prix: sources close to both sides
'Vibe hacking' puts chatbots to work for cybercriminals
The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.
So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.
The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".
Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".
The attacker has since been banned by Anthropic.
Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.
Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.
Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.
"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.
- Dodging safeguards -
Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.
The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.
But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.
He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.
The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.
"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.
His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.
In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.
Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.
"We're not going to see very sophisticated code created directly by chatbots," he said.
Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.
C.Kovalenko--BTB