“취약점 공개도 전에 해킹”…‘프론티어 AI’에 주요국 금융권 부산한 대응
Recent reports indicate that the AI agent model known as "Frontier AI," a cutting-edge model that emerged in April 2024, has been suspected of conducting simultaneous hacks on major global financial institutions. Countries' financial sectors and regulatory bodies are responding by redesigning existing security systems, moving from the traditional "preventive reliance" method to the "zero trust principle," where security assumes hackers have already breached.
According to the Financial Security Agency and the International Financial Center, starting in early April, OpenAI, Google, Microsoft, and others released new Frontier AI models, including "Claude Mitos Preview." These AI models possess the capability to autonomously detect system vulnerabilities and generate code to exploit them.
The Mitos model, however, did not make this capability widely available and, instead, restricted access to 40-plus critical infrastructure operators through an "industrial consortium called Project Glasswing." AI agents are capable of setting and executing plans, adjusting and reviewing them independently, without continuous human intervention.
Professor Cheon Young-sung from Konkuk University and Kyunghee University, a national AI strategy advisor, reported in May that "Mitos has crossed the critical point where AI models begin to outperform human experts in the security sector. Cybersecurity defenses have, in fact, crumbled as the attack surface is now as powerful as the defense."
While financial companies could leverage such AI models to find previously undiscovered security vulnerabilities within days, attackers could do the same, discovering and exploiting vulnerabilities. According to the cybersecurity statistics platform ZeroDayClock, the average time it takes for hackers to attempt a breach after a vulnerability is discovered has shortened from several months last year to just a few hours or even negative hours, meaning before the vulnerability is disclosed.
This indicates a higher number of hacking attempts occurring before or at the time of vulnerability disclosure. Consequently, major global financial institutions have convened emergency meetings following the announcement of Mitos Preview to devise response measures in terms of supervision and policy. Financial institutions such as JP Morgan Chase, City, Goldman Sachs, and Bank of America have started responding to the vulnerabilities in Mitos Preview by discovering and patching hundreds to thousands of vulnerabilities in a matter of hours.
Andrew Bailey, the CEO of the UK's Bank of England, has described Frontier AI as a "model that will shake up the entire cyber risk landscape." The International Monetary Fund (IMF) anticipates that the security response direction of countries' financial sectors will shift from the traditional "preventive" approach to "prevent, deter, and recover."
The existing "vulnerability management" approach, where vulnerabilities are identified and patched before they can be exploited, is no longer applicable. Instead, a new "exploit defense" approach will prevail, where threats are blocked or neutralized in real-time as soon as an attack is detected. To achieve this, major financial companies are now presenting "zero trust" (Zero Trust or least trust) as the primary response direction.
According to the International Financial Center, the U.S. federal government, Hong Kong's HSBC, JP Morgan Chase, and Australia's ANZ Bank are actively adopting the zero trust principle. Zero trust involves minimizing trust in users, devices, and applications, requiring continuous authentication and verification for all access requests, granting only the necessary permissions for each business operation at the appropriate time and session.
Written by urgent.news from Hankyoreh's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.