Threat Intelligence, AI/ML

Criminals using AI vibe coding tools to develop malware, study says

Adobe Stock

The Register reports that the rapid adoption of vibe coding, using AI-powered tools to generate software, is now being leveraged by cybercriminals to develop malware, raising significant new security challenges for enterprises.

Palo Alto Networks Unit 42 senior director Kate Middagh confirmed that threat actors are actively using these platforms, citing "incontrovertible proof" like API calls to OpenAI embedded directly within malicious code. However, a silver lining for defenders is that AI-generated attacks often contain errors, such as ransom notes with typos or "security theater," ineffective code that looks threatening but lacks proper implementation due to AI hallucinations or rushed development. Middagh noted that most organizations lack formal risk assessments or controls for these tools, with only half having any limits on AI usage.

To address these risks, Palo Alto Networks has introduced the "SHIELD" framework, a set of security principles designed to be integrated throughout the AI-assisted development lifecycle. SHIELD emphasizes Separation of Duties, ensuring a Human in the Loop for code review, Input/Output Validation, Enforcing Security-Focused Helper Models, applying Least Agency permissions, and employing Defensive Technical Controls to mitigate supply chain and execution risks.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds