Is ChatGPT a threat to our cybersecurity?

Published February 13, 2023
Author: Ash Khan

Is ChatGPT a threat to our cybersecurity?

Published February 13, 2023
Author: Ash Khan

 

ChatGPT has been the internet’s new favorite toy since its introduction in November. The AI-powered natural language processing tool quickly gathered over 1 million users. They utilized the web-based chatbot for everything from creating wedding speeches and hip-hop songs to producing academic essays and more.

 

Not only has ChatGPT’s human-like abilities taken the internet by storm, but it has also put several industries on edge. A New York school banned ChatGPT over concerns that students can cheat with it. It has already replaced copywriters.

The cybersecurity sector, which was unaware of the potential consequences of current AI, is taking note as well. They fear that hackers can misuse ChatGPT with low resources and no technical understanding.

 

So, what are security Concerns?

cybersecurity website demonstrated ChatGPT can write a phishing email containing a harmful payload when combined with OpenAI’s code-writing engine. As Check Point reports, such cases are indicative of ChatGPT’s potential to significantly alter cyber threat landscapes. This represents yet another step forward as cyber capabilities get more sophisticated and effective.

TechCrunch claims using the chatbot, they were able to construct a legitimate-looking phishing email. When they asked ChatGPT to create a phishing email, the chatbot declined. However, by significantly changing the request, they were able to easily overcome the software’s built-in guardrails.

ChatGPT is able to create legitimate-sounding phishing emails, the most common attack vector for ransomware. Many online website security professionals think it will be adopted by cybercriminals, especially those who cannot speak English natively. Due to ChatGPT’s more convincing English, hackers can use it for a variety of social engineering attacks.

 

The prospect of a chatbot writing convincing language and engaging in genuine exchanges isn’t that far-fetched. Using ChatGPT, you can create lifelike text in seconds by instructing it to pretend to be a GP surgeon. It’s easy to see how threat actors may utilize this as a force multiplier.

Check Point has also lately raised concerns about the chatbot’s apparent capacity to assist attackers in writing dangerous malware. According to the researchers, on several occasions where hackers with little technical expertise boasted about using ChatGPT’s AI smarts for harmful objectives. A hacker showed ChatGPT built code that took files of interest, compressed them, and transferred them over the web. Another person provided a Python script that they claimed was the first script they had ever written. While the malware appeared to be harmless, however, it could be updated to encrypt someone’s PC fully without any user intervention.

How tough could it possibly be?

 

security service website researcher demonstrated ChatGPT was leveraged to create a World Cup-themed phishing email and macOS-targeting malware. They instructed the chatbot to construct code in Swift, the programming language used to create apps for Apple devices. It could connect to a web server over an encrypted connection and deliver Office documents to the Mac before encrypting those documents.

Unsurprisingly, the capacity of ChatGPT to develop harmful code raised eyebrows across the industry. Some experts have also moved to dispel fears that an AI chatbot may transform inexperienced hackers into full-fledged crooks. A security researcher criticized Check Point’s assertions that ChatGPT will supercharge cyber criminals who stink at coding.

The researcher said that they must register domain names and manage infrastructure. They must update websites with fresh material. Moreover, they must ensure that software that barely works on one platform continues to hardly operate on another. They must evaluate their infrastructure for health and keep an eye on what is going on in the press. They must ensure that their campaign does not get up in an article about the top 5 most embarrassing phishing fails. Getting and utilizing malware is only a minor fraction of the work that goes into becoming a bottom-feeder cybercriminal.”

Is anyone in favor of ChatGPT?

Some argue that ChatGPT’s capacity to build dangerous code has an unintended consequence. Defendants can utilize ChatGPT to develop code to emulate adversaries or even automate chores to make their lives simpler. It has been utilized for several outstanding activities, including tailored teaching, creating newspaper articles, and writing computer code. However, it should be highlighted that it might be unwise to totally trust the output of text and code created by ChatGPT. The code it creates could contain security concerns or vulnerabilities. The resulting text might potentially contain plain factual inaccuracies. According to an online security website, if ChatGPT learns sufficiently from its input, it can assess possible attacks and provide suggestions to improve security.

 

Summary

Not only security specialists are divided on the role ChatGPT will play in the future of cybersecurity. We were also intrigued to know what ChatGPT had to say when we asked the chatbot the question.

It’s difficult to foresee how ChatGPT or any other technology will be utilized in the future. Since it relies on how it is deployed and the objectives of individuals who use it. Ultimately, the influence of ChatGPT on cybersecurity will be determined by how it is used. It is critical to be aware of such hazards and to take proper precautions to reduce them.