Cisco Talos reveals hackers exploiting generative AI tools to create malware, automate attacks, and bypass cybersecurity protections.

Hackers are using top generative AI models to develop malware, automate cyberattacks and identify software vulnerabilities, according to a report from Cisco Talos intelligence group. The research reveals how threat actors are exploiting generative AI models by bypassing built-in safety controls on platforms including Claude Code, Codex, Cursor and Gemini, creating new challenges for cybersecurity teams and AI developers.

AI Tools Become Targets for Cybercriminal Operations

Researchers at Cisco Talos examined threat actors' chat logs and exposed prompt histories to learn how cybercriminals manipulate AI coding assistants. The findings showed that attackers used these tools for malware creation, vulnerability research and automated attack planning.

Claude Code from Anthropic, Codex from OpenAI, Cursor and Google’s Gemini are designed to assist developers and security professionals. However, the same capabilities that support legitimate coding and security testing can also be redirected toward harmful activities when safeguards are bypassed.

Key findings from the Cisco cybersecurity report include:

  • Hackers used AI models to develop malicious code
  • Threat actors bypassed restrictions using simple prompts
  • Attackers targeted vulnerabilities through AI-assisted research
  • Compromised accounts supported unauthorized AI operations
  • Cybercriminals exploited enterprise resources for attacks

Simple Jailbreak Methods Challenge AI Safety Systems

The Cisco report highlighted that attackers did not require advanced methods to overcome AI safety filters. Instead, many relied on social engineering techniques, such as claiming involvement in authorized security testing, stating they had administrative approval, or restarting conversations to remove previous restrictions.

Nick Biasini, senior technical leader at Cisco Talos, noted that AI providers face difficulties balancing security protections with the needs of legitimate cybersecurity researchers. Security professionals often depend on AI tools for vulnerability assessments and red-team exercises, making strict restrictions difficult to implement without limiting useful applications.

The report also found that some attackers used stolen enterprise API tokens and compromised accounts to access computing resources. This allowed cybercriminals to conduct operations without investing in their own infrastructure.

Growing Need for Stronger AI Cybersecurity Protection

The emergence of automated cyberattacks and AI-powered malware development underscores the importance of security procedures. Experts caution that companies should put in place extra monitoring, access controls and cybersecurity rules rather than relying just on AI model protections.

The results highlight issues with prompt manipulation, AI vulnerability exploitation and coding abuse. Security teams need to get ready for increasingly complex AI-based threats as generative AI becomes more widely used in enterprises.

Business Fortune believes that stronger AI security measures, responsible development, and vigilant organizations are essential as cybercriminals increasingly exploit generative AI capabilities for malicious activities worldwide.

FAQs

What did the Cisco Talos report reveal about generative AI misuse?

The Cisco Talos report revealed that hackers are exploiting generative AI models to develop malware, automate cyberattacks, and discover software vulnerabilities.

How are hackers bypassing security protections in AI models?

Threat actors are bypassing AI safety filters through simple jailbreak techniques, misleading prompts, fake authorisation claims, and repeated chat attempts.

Why are AI coding assistants attracting cybercriminal attention?

AI coding assistants can generate and analyse code quickly, making them useful for developers while also creating opportunities for attackers to misuse their capabilities.

Which generative AI tools were highlighted in the Cisco cybersecurity findings?

The report identified risks involving Claude Code, Codex, Cursor, and Gemini, which attackers attempted to manipulate for malicious activities.

What steps can companies take to prevent AI-powered cyberattacks?

Businesses can reduce risks by securing API access, monitoring AI usage, strengthening identity controls, and combining AI protections with traditional cybersecurity measures.