Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    Does Arc Raiders Actually Have a Storyline?

    November 18, 2025

    As consumers ditch Google for ChatGPT, Peec AI raises $21M to help brands adapt

    November 18, 2025

    OPPO Find X9 Series Launching in India at 12 noon Today: How to Watch the Livestream? What to Expect

    November 18, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      As consumers ditch Google for ChatGPT, Peec AI raises $21M to help brands adapt

      November 18, 2025

      a16z-backed super PAC is targeting Alex Bores, sponsor of New York’s AI safety bill — he says bring it on

      November 18, 2025

      Meta releases a new tool to protect reels creators from having their work stolen

      November 18, 2025

      Ramp hits $32B valuation, just three months after hitting $22.5B 

      November 18, 2025

      Sequoia-backed fintech Aspora will let Indian diaspora pay bills back home

      November 17, 2025
    • Mobiles

      OPPO Find X9 Series Launching in India at 12 noon Today: How to Watch the Livestream? What to Expect

      November 18, 2025

      Lava Is Letting People Try The Agni 4 At Home Before Launch

      November 18, 2025

      OPPO Reno15 and Reno15 Pro Launched With Dimensity 8450 and 200MP Camera: Check Price, Specs, and India Launch

      November 17, 2025

      Wobble Smartphone Camera Features Surface Online Ahead of Launch in India on November 19

      November 17, 2025

      Nothing Phone (3a) Lite Launching In India On November 27

      November 17, 2025
    • Gaming

      Does Arc Raiders Actually Have a Storyline?

      November 18, 2025

      6 Crazy Things Only Gojo and Sukuna Can Do In Jujutsu Kaisen

      November 18, 2025

      After Kurama, Naruto Uzumaki’s Next Power-Up Will Give Him A New Inner Demon

      November 18, 2025

      Baldur’s Gate 3: Best Ranger Class Build

      November 18, 2025

      Re:Zero Season 4 Release Date Confirmed

      November 17, 2025
    • SEO Tips
    • PC/ Laptops

      Apple Reportedly Reserving OLED Displays for M6 Pro and M6 Max MacBook Pro Models

      November 10, 2025

      Apple Reportedly Working on a Budget MacBook Featuring iPhone Chip: Expected Launch and Price

      November 5, 2025

      Acer Predator Helios Neo 16 AI and 16S AI Gaming Laptops Launched in India: Check Pricing and Specifications

      November 4, 2025

      COLORFUL Launches Rimbook L1: Affordable Laptop For Everyday Use

      November 4, 2025

      Acer Expands Lite Series With New Nitro Lite 16 Laptop in India

      November 3, 2025
    • EV

      Here’s How Much It Costs

      November 15, 2025

      Sodium-Ion Batteries Have Landed In America. The Hard Part Starts Now

      November 15, 2025

      Mazda Begins Testing Its Long-Overdue U.S. EV

      November 14, 2025

      Volkswagen Adds Smartwatch Support For U.S. Vehicles

      November 14, 2025

      TATA.ev expands charging footprint with 14 new manned MegaChargers across AP, Telangana

      November 14, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - Vibe hacking and why cybersecurity experts are worried
    Featured

    Vibe hacking and why cybersecurity experts are worried

    KavishBy KavishOctober 8, 2025No Comments6 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Vibe hacking and why cybersecurity experts are worried
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Although still in the nascent stages, vibe hacking could become a serious concern going forward. Mint explains what makes vibe hacking so dangerous and difficult to detect.

    Table of Contents

    Toggle
    • What is vibe hacking?
    • What makes vibe hacking dangerous?
    • What makes it particularly difficult to detect vibe hacking?
    • Which industries are likely to be affected by vibe hacks?
    • How should companies combat vibe hacking?
    • What are the security tools to fight this menace?

    What is vibe hacking?

    Vibe hacking is the malicious twin of vibe coding, where hackers use AI to generate malicious code at scale. In vibe coding, users, with the help of simple language, can get an artificial intelligence coding agent to write lines of code from natural language prompts.

    There are two kinds of vibe hacking. In the first, hackers use an existing vibe coding platform to write malicious code to attack existing code bases. Vibe coding platforms, unless given access, aren’t privy to the companies’ code base. When given, however, developers can use a vibe coding platform to recommend code for products they’d like to build.

    “Instead of building, if someone gets access to your codebase, it can actually tell the platform exactly what to do to extract data or do something malicious, that is very risky,” said Saket Modi, co-founder and chief executive of Safe Security, a cyber risk management company.

    The other kind is where a hacker doesn’t need to be an expert in breaching systems; instead, they use natural language to get a vibe of a coding platform to write malicious code.

    It’s what happened in the case of a cybercriminal using Anthropic’s Claude Code agent. In August, the US-based AI startup flagged that a hacker had used Claude Code to automate reconnaissance, harvest user credentials, and penetrate networks. Before Anthropic detected the misuse of its coding agent, the hacker had targeted 17 different organisations across healthcare, the emergency services, and government and religious institutions.

    Claude Code was used not only to target these companies but also to make strategic decisions on what data to harvest as well as how to craft psychologically targeted extortion demands, according to Anthropic’s Threat Intelligence report.

    What makes vibe hacking dangerous?

    “Because generative AI lowers the barrier to writing and refining code, criminals with little technical skill can orchestrate sophisticated attacks,” according to Aaron Rose, office of the chief technology officer at Check Point Software. That also means the frequency of cyberattacks increases due to the low barrier to entry in creating them.

    What’s more, vibe hacking attacks are capable of circumventing traditional cyber defence systems. They don’t necessarily need to break into networks or exploit software vulnerabilities either.

    “Attackers can manipulate the ‘intent’ layer of AI systems, tricking models into exfiltrating sensitive data or performing harmful actions through carefully crafted language alone,” said Operant AI co-founder and CEO Vrajesh Bhavsar. Operant AI is a cybersecurity company focused on securing AI systems.

    What makes it particularly difficult to detect vibe hacking?

    Vibe hacking can often be mistaken for conventional breaches. Vibe hacked attack payloads use programming languages like PowerShell and Python and are able to avoid traps left by a company’s cyber security team. Additionally, because of the changing code, there are no static malware samples for experts to analyse and work against either.

    Vibe hacks can look like innocuous files or content, which contain hidden prompts to attack a system. This can range from context poisoning, where shared memory between AI agents is contaminated to slipping in malicious logic into open-source code.

    “Another common pattern is privilege escalation, where an over-permissioned agent ends up misusing credentials,” said Bhavsar. “Zero-click attacks are particularly concerning because they don’t require any human action, just opening a file or connecting to a poisoned tool is enough.”

    Which industries are likely to be affected by vibe hacks?

    Hackers tend to target organisations that possess a significant amount of sensitive information or are considered critical infrastructure. Therefore, industries such as banking, financial services and insurance (BFSI), healthcare, government, and even media are targets for vibe hackers.

    “Healthcare institutions hold vast amounts of sensitive patient data, credentials, and billing information, making them key targets for hackers who can monetize this critical data on the dark web,” said Ajay Biyani, vice president of APJ, India, Middle East & Africa at US-based cybersecurity company Securonix. “The manufacturing sector, which is transforming with Industry 4.0, comes with rising cyber risks due to loT device integration and growing automation, exposing manufacturers to vibe hacking.”

    Hackers also target critical infrastructure, such as energy and utilities, which can have significant national security implications. Even retail and e-commerce aren’t safe on account of companies in the sector handling large volumes of customer data and online transactions.

    Sosafe, a cybersecurity awareness training and human risk management provider, released a report earlier this year that showed 87% of security professionals at companies encountered an AI-driven cyberattack in the last year. The survey covered 500 global security professionals as well as 100 SoSafe customers across 10 countries.

    How should companies combat vibe hacking?

    With AI attacks becoming more sophisticated and enterprises adopting AI into their ecosystems, cybersecurity experts suggest limiting AI tool privileges and access to data.

    As AI threats grow, cybersecurity experts recommend restricting AI tool privileges and data access.

    “Because each Al-generated script is unique, defenders must look for unusual patterns such as unexpected outbound connections to Al providers, scripts invoked by unusual processes, or data exfiltration disguised as routine traffic,” said Rose.

    The other way to fight vibe hacking attempts is by taking on a multi-layered approach, which includes AI-powered security tools as well as training employees to recognise AI-generated threats. “For platforms, especially those running SPAs, regular code reviews and automated vulnerability scanning are critical,” said Apeksha Kaushik, principal analyst at Gartner, a research and advisory firm.

    Cybersecurity company, Darktrace, backed by global investment firm KKR found that 78% of companies’ chief information security officer believe AI is having an impact on cyber threats. Additionally, nine in ten survey participants agree that AI-powered threats will continue to have a significant impact on their organization for the next one to two years.

    What are the security tools to fight this menace?

    When dealing with third-party vendors, asking about their AI use and software bill of materials can also be valuable. Operant AI, for instance, maps every agent identity, tool, access flow, and data touchpoint within a company’s environment.

    “We monitor agents continuously, not just for network activity but for semantic and behavioural anomalies,” said Bhavsar. As attack sophistication and frequency increase, cybersecurity experts argue that the only way forward is to develop and maintain AI-enabled solutions. “You fight fire with fire. On the defence side, everything has to be AI-enabled,” said Safe Security’s Modi.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    Does Arc Raiders Actually Have a Storyline?

    November 18, 2025

    As consumers ditch Google for ChatGPT, Peec AI raises $21M to help brands adapt

    November 18, 2025

    OPPO Find X9 Series Launching in India at 12 noon Today: How to Watch the Livestream? What to Expect

    November 18, 2025

    6 Crazy Things Only Gojo and Sukuna Can Do In Jujutsu Kaisen

    November 18, 2025

    a16z-backed super PAC is targeting Alex Bores, sponsor of New York’s AI safety bill — he says bring it on

    November 18, 2025

    Meta releases a new tool to protect reels creators from having their work stolen

    November 18, 2025

    Comments are closed.

    Top Reviews
    Editors Picks

    Does Arc Raiders Actually Have a Storyline?

    November 18, 2025

    As consumers ditch Google for ChatGPT, Peec AI raises $21M to help brands adapt

    November 18, 2025

    OPPO Find X9 Series Launching in India at 12 noon Today: How to Watch the Livestream? What to Expect

    November 18, 2025

    6 Crazy Things Only Gojo and Sukuna Can Do In Jujutsu Kaisen

    November 18, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.