BIS warns AI could cut banks’ patching window to minutes

Advanced AI has cut the time banks may have to repair software flaws from weeks to minutes, according to a new Bank for International Settlements paper that calls for faster security decisions and patching. Summary The BIS paper says AI can help find software flaws and turn them into working attacks. Its authors warn that scheduled security checks and patching may be too slow. U.S. and overseas authorities are pressing financial firms to improve cyber response and recovery. A July incident involving OpenAI agents and Hugging Face showed how a test could reach real systems The Bank for International Settlements paper, published on Sep. 9 by its Financial Stability Institute, says banks need to shorten the time between finding a weakness, approving a fix, and installing it. Its authors identify AI systems that can find vulnerabilities and turn them into working attacks as the main change facing financial firms. “The window between vulnerability discovery and exploitation has narrowed from weeks to minutes,” the authors wrote. The paper does not say every flaw can be exploited that quickly. It argues that regular security reviews and fixed maintenance schedules may leave firms exposed when an attack can be prepared before the next planned repair. BIS says faster attacks require faster bank decisions According to the paper, the U.K. Financial Conduct Authority has found that firms are struggling to respond as quickly as vulnerabilities are being discovered. The Institute of International Finance has urged firms to install urgent fixes outside normal maintenance periods, even when doing so requires planned downtime. Separate voluntary guidance from the U.K.’s Cross Market Operational Resilience Group anticipates that some repair periods could fall from weeks to days or hours, the BIS authors said. Faster patching also depends on management: a security team cannot install a high-impact fix promptly if the people responsible for approving an interruption to banking services are unavailable or unclear about who can make the call. You might also like: Brazil central bank prepares crypto monitoring system after $180M cyberattack The report therefore treats cyber response as a matter for senior management as well as technical staff. It says boards need clear information about emerging threats, while institutions need decision processes that let them assess a flaw, approve a response, and protect essential services without waiting for a routine review. In the United States, the paper points to New York financial regulator guidance issued in May for firms facing a heightened cyber threat environment. According to the BIS, the New York Department of Financial Services included advances in AI among the developments that could change cyber risks and asked regulated entities to consider stronger detection, preparation, response, and recovery measures. The U.S. connection also extends to outside technology providers. In a Sep.
عنوان اصلی (انگلیسی): BIS warns AI could cut banks’ patching window to minutes
مشاهدهی خبر کامل در منبع ↗ بازگشت به Mythosاین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.