Even Unskilled Hackers Have Game Now With Vibe Coding

Recent reports identified a cyber criminal actively using AI-generated malware in a real cyber attack.

A cybersecurity company, Huntress, recovered and rebuilt the AI script from an incident that occurred in June 2026. According to Huntress, the tool had several identifiers that revealed the use of AI, including a placeholder server name the AI supplied as an example that was left in.

Other AI signs included five different fallback methods for certain actions, a "fondness" for colorful console output, errors, and an HTML report summarizing the theft after it was completed.

The cyber criminal allegedly got access to the system with stolen credentials and used the AI-generated script to scout the network for information. The script located the controller, then harvested active directory users, computers, groups, and trusts into spreadsheets. Legitimate cloud tools were responsible for the data exfiltration.

Source: https://www.infosecurity-magazine.com/news/vibe-coded-malware-ai-powershell/

Commentary

AI-generated scripts are allowing unsophisticated cyber criminals to engage in cyber attacks far beyond their levels of expertise.

The most concerning aspect of the cyber attack illustrated in the source was not the AI tool, but the cybercriminal who ran it and how it was created. According to industry experts, the code was messy, over-engineered, and filled with AI giveaways. Nevertheless, it worked.

This cyber attack shows how bad actors of all levels are able to weaponize AI. Low-level criminals are now able to create and run successful AI-generated scripts. Previously, a certain level of expertise and know-how was required to hack into most systems. Fewer barriers to commit hacks means a likely uptick in cyber attacks.

One reason is the surge of "vibe coding", which refers to using AI to generate software by prompting it in plain, casual language. No manual code writing is needed. The developer simply prompts the AI regarding what tool is needed, guides the AI to generate and test the desired result, and the then the developer further refines it with the AI until satisfied.

Vibe coding has allowed even the most unremarkable attackers to create unique, custom tools.

To help reduce exposure to AI-generated tools, organizations should:

· Assume credential theft is the fastest path to whole system compromise

· Utilize multi-factor authentication

· Train all staff on cybersecurity, especially on phishing detection, including phishing simulations

· Require all staff to use strong, unique passwords for all organizational accounts and devices

· Invest in anti-virus protection that is AI-specific

· Monitor systems for abnormal network usage, irregular patterns, or unusual data requests

· Continually test systems to find vulnerabilities, fixing those security gaps immediately

The final takeaway is that AI-generated malware is providing a larger group of less sophisticated attackers a bite at the cyber attack apple. Because these AI tools may bring more cyber attack attempts, organizations are wise to proactively implement cybersecurity fundamentals.

Cybersecurity training, investing in the right threat detection tools, and quickly patching security gaps will always be great ways to protect your organization, even against AI-generated malware.

Source: https://www.ibm.com/think/insights/defend-against-ai-malware

Finally, your opinion is important to us. Please complete the opinion survey:

Product

Articles

Even Unskilled Hackers Have Game Now With Vibe Coding

Attackers with low-level expertise are using AI to launch attacks way above their skill level. We examine the threat and explain why cybersecurity fundamentals are still the best defense.

Is Working With Dangerous Patients Workplace Retaliation?

A New Jersey psychiatric hospital must pay $1 million for retaliating against a physician who provided testimony in a class action regarding workplace and patient safety. We examine how an increased workload can be viewed as retaliation.

The Ugly Secret Of Departing Employees And Trade Secret Theft?

Apple sued a former engineer and alleged he stole valuable trade secrets after leaving to work for another company. We discuss the case and how organizations can help protect their information.

Underground AI Supercharges Phishing Attacks On Employers

Security researchers report that cybercriminals are using underground and jailbroken AI models to write sophisticated malware and phishing messages. We comment on how employers can respond.

Timing Mistakes: Termination After Accommodation Requests

A termination's timing brings litigation after a medical facility fires a worker soon after her request for an accommodation. We examine and discuss the termination risks for healthcare employers.