-
DR Congo capital wary of Ebola nightmare
-
Yamaguchi on course for fourth badminton world crown
-
Swedish police name 17-year-old girl as victim in school sword attack
-
Man Utd humiliated by Hull in dismal start to Premier League season
-
South Korea sends first container ship through Arctic route
-
Anthropic market debut could break SpaceX IPO record: media
-
Trescothick eager to keep England job despite Hussey approach
-
Pope's 'couturier of the sacred' fueled by faith
-
Indonesia deploys hundreds of soldiers to tackle Borneo fires
-
Duplantis locked in on 'grinding' for big bars
-
The last lap: Fans, drivers bid fond farewell to Dutch GP
-
Stokes says decision to leave Headingley off Ashes roster 'shambolic'
-
Silesia Diamond League: four events to watch
-
New arrival Rodri to miss Elche opener: Barca's Flick
-
Russell wins Dutch GP sprint race, Antonelli fourth
-
Atletico's Alvarez to return against Villarreal: Simeone
-
Mercedes driver George Russell wins Dutch GP sprint race
-
Dozens of civilians killed, kidnapped as jihadists clash in Nigeria
-
Ukraine strikes kill two children after Russia's deadly mall attack
-
Former envoys urge joint French, UK action on Palestinian territories
-
Pope visits San Marino, before addressing Italian political gathering
-
Australia lead by 101 in 2nd Bangladesh Test as 18 wickets fall on day one
-
Trump tariffs heap up as Canada tries to curb US reliance
-
'Aura' battles leap from social media to Latin America streets
-
Australia lose three wickets after skittling Bangladesh for 64
-
US, Canada fail to reach trade pact to avert Trump tariffs
-
Bangladesh all out for 64 in 2nd Test after Starc masterclass
-
Sudan farms lie barren as El Nino leaves Nile banks dry
-
Odyssey effect: stars sell Greece to a new wave of US tourists
-
Arctic shipping a daunting prospect in hotly contested region
-
South Korea to send first container ship through Arctic route
-
In US, rare earths extracted from coal mine wastewater
-
Starc takes 5-11 to leave Bangladesh reeling in 2nd Test
-
Nakashima pounds Fritz, Bejlek beats Keys in Cincinnati upsets
-
Injured Rune withdraws from US Open
-
Canadian negotiator says 'more work to do' on US trade deal
-
Nakashima knocks out Fritz to reach Cincinnati semi-finals
-
'Solid' Clark takes solo lead at BMW Championship
-
Ukraine says 'cynical' Russian strike on shopping centre killed 16
-
Arteta hails Arsenal's desire after perfect start to title defence
-
TikTok to pay $400 mn settlement in US children's privacy case
-
Betis down Real Sociedad in La Liga opener
-
MLS fines Messi for striking an opponent
-
Mexican governor resumes job despite US drug charges
-
Gouiri double fires Marseille past Strasbourg in Ligue 1 opener
-
Arsenal rout Coventry to open Premier League season in style
-
Mavericks buy out Thompson, now reportedly bound for Heat
-
Giant-killer Bejlek overhauls Keys to reach Cincinnati semi-finals
-
England v Pakistan first Test: Three talking points
-
Man Utd agree deal for Brighton midfielder Baleba: reports
'Vibe hacking' puts chatbots to work for cybercriminals
The potential abuse of consumer AI tools is raising concerns, with budding cybercriminals apparently able to trick coding chatbots into giving them a leg-up in producing malicious programmes.
So-called "vibe hacking" -- a twist on the more positive "vibe coding" that generative AI tools supposedly enable those without extensive expertise to achieve -- marks "a concerning evolution in AI-assisted cybercrime" according to American company Anthropic.
The lab -- whose Claude product competes with the biggest-name chatbot, ChatGPT from OpenAI -- highlighted in a report published Wednesday the case of "a cybercriminal (who) used Claude Code to conduct a scaled data extortion operation across multiple international targets in a short timeframe".
Anthropic said the programming chatbot was exploited to help carry out attacks that "potentially" hit "at least 17 distinct organizations in just the last month across government, healthcare, emergency services, and religious institutions".
The attacker has since been banned by Anthropic.
Before then, they were able to use Claude Code to create tools that gathered personal data, medical records and login details, and helped send out ransom demands as stiff as $500,000.
Anthropic's "sophisticated safety and security measures" were unable to prevent the misuse, it acknowledged.
Such identified cases confirm the fears that have troubled the cybersecurity industry since the emergence of widespread generative AI tools, and are far from limited to Anthropic.
"Today, cybercriminals have taken AI on board just as much as the wider body of users," said Rodrigue Le Bayon, who heads the Computer Emergency Response Team (CERT) at Orange Cyberdefense.
- Dodging safeguards -
Like Anthropic, OpenAI in June revealed a case of ChatGPT assisting a user in developing malicious software, often referred to as malware.
The models powering AI chatbots contain safeguards that are supposed to prevent users from roping them into illegal activities.
But there are strategies that allow "zero-knowledge threat actors" to extract what they need to attack systems from the tools, said Vitaly Simonovich of Israeli cybersecurity firm Cato Networks.
He announced in March that he had found a technique to get chatbots to produce code that would normally infringe on their built-in limits.
The approach involved convincing generative AI that it is taking part in a "detailed fictional world" in which creating malware is seen as an art form -- asking the chatbot to play the role of one of the characters and create tools able to steal people's passwords.
"I have 10 years of experience in cybersecurity, but I'm not a malware developer. This was my way to test the boundaries of current LLMs," Simonovich said.
His attempts were rebuffed by Google's Gemini and Anthropic's Claude, but got around safeguards built into ChatGPT, Chinese chatbot Deepseek and Microsoft's Copilot.
In future, such workarounds mean even non-coders "will pose a greater threat to organisations, because now they can... without skills, develop malware," Simonovich said.
Orange's Le Bayon predicted that the tools were likely to "increase the number of victims" of cybercrime by helping attackers to get more done, rather than creating a whole new population of hackers.
"We're not going to see very sophisticated code created directly by chatbots," he said.
Le Bayon added that as generative AI tools are used more and more, "their creators are working on analysing usage data" -- allowing them in future to "better detect malicious use" of the chatbots.
Q.Jaber--SF-PST