-
Fernandez logs record lap at Indonesia MotoGP practice
-
'I completely trust the club,' says Man City boss Maresca
-
Navi Pillay: S.Africa's global rights activist and Nobel winner
-
'10 out of 10' Quintana reminisces over dream Vuelta win
-
Ufunded Launches “Spotlight” Series, Documenting the Minds Shaping Modern Trading
-
Maddinson given shock recall but fails to score
-
Russell goes fastest in practice for smoggy Singapore GP
-
Navi Pillay, South African rights champion, wins Nobel Peace Prize
-
For exiled Russian director Zvyagintsev, triumph without belonging
-
Saudi Arabia says three killed at airport as Yemen war expands
-
Home hope Zheng storms into China Open semi-finals
-
Everton's US owners mull sale of club two years after takeover
-
Zverev churns out win in Shanghai Masters opener
-
Ukraine takes Russia fight to 'scorching sands' of Sahel
-
Hurricane Isaias strengthens en route to US Gulf Coast
-
Chinese AI tool pulled to prevent 'misuse' after South Korea hacks
-
US activists deploy poll volunteers over Trump intimidation fears
-
Asian stocks mostly up as traders weigh AI, oil dips after surge
-
Saint Laurent designer Vaccarello leaves after glittering decade
-
Walking through flames: orangutans rescued in Indonesia fires
-
'Tough to stay here': Nepal flood survivors wait for homes
-
LeBron shines in pre-season debut for re-tooled 76ers
-
Malaysia closes schools in capital, parts of country due to haze
-
Okinawa resolution calls for revision of US forces pact after murder
-
Buccaneers stun Cowboys for first win of NFL season
-
Verdict expected Friday in Mexico trial over murders of Australia, US surfers
-
Activists hope trial will stop 'forever chemicals' at Italy plant
-
New York mayor says asking Trump to withdraw ICE after shooting
-
Guardians rally for 9-5 victory over White Sox to stay alive in MLB playoffs
-
Walking through flames: orangutan rescued in Indonesia fires
-
Asian stocks mixed amid AI concerns, oil dips after surge
-
James shines in pre-season debut for re-tooled 76ers
-
Wallabies expect fast-paced All Blacks in Bledisloe opener
-
Fuel, fertilizer costs strain US farmers' support for Republicans in midterms
-
Tech scammer Elizabeth Holmes focus of documentary by absurdist Nathan Fielder
-
Trump's 'super intelligence' rebrand to sell AI faces uphill battle
-
Climate hopes shift from politics to the courts
-
Fiji demands US provide evidence Chinese official paid bribes for Beijing
-
Will Nobel Peace Prize pick make waves at the White House?
-
More than just football: How scandal-tainted City led Manchester's rebirth
-
Trump rules out new Iran attack before US midterm elections
-
Record Eden Park streak creates tension for All Blacks
-
Far-right influencer shows Israel's coarse political turn
-
EU trade chief seeks 'tangible outcomes' in China talks
-
Seals and sea lions get hearing tested at Australia zoo
-
Man City face Anfield cauldron after guilty Premier League verdicts
-
Mourinho's Real Madrid playing catch-up in Clasico countdown
-
CNN, MS Now, Politico urge judge to extend White House access
-
Joy as USS Lincoln back home after troubled Gulf deployment
-
Trump administration to launch new vaccine research center
'Vibe hacking' puts chatbots to work for cybercriminals
The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.
So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.
The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".
Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".
The attacker has since been banned by Anthropic.
Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.
Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.
Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.
"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.
- Dodging safeguards -
Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.
The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.
But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.
He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.
The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.
"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.
His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.
In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.
Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.
"We're not going to see very sophisticated code created directly by chatbots," he said.
Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.
Q.Jaber--SF-PST