Briev
Live
Technology

Cisco Talos finds hackers exploiting major AI coding models to craft malware

Cisco’s Talos unit reports that cybercriminals are leveraging leading generative AI tools such as Claude Code, Codex, Cursor and Gemini to create malicious code and automate attacks.

Cisco’s Talos intelligence team uncovered that hackers are repurposing top generative AI coding models—including Anthropic’s Claude Code, OpenAI’s Codex, Cursor and Google’s Gemini—to develop malware and automate cyber-offensives. By examining accidentally exposed prompt logs, the team saw threat actors bypassing safety mechanisms through straightforward social-engineering prompts rather than sophisticated technical exploits.

Common workarounds involved asserting involvement in authorized “ethical hacking” contests, claiming administrative rights, or restarting chats mid-task. Some attackers further leveraged stolen corporate API credentials to execute their operations on victim cloud infrastructure, avoiding the cost of their own compute. Cisco warns that these easy-to-apply tricks highlight a growing challenge for AI developers, as the same capabilities meant to aid security professionals can be turned against them. Experts recommend that organizations supplement model-level protections with broader security controls.

Why it matters

Malicious use of AI coding tools could accelerate the creation of sophisticated malware, raising cyber risk for businesses and users.

In this story

generative AImalwarecyberattackClaude CodeCodexCursorGeminijailbreakAPI tokens