Urgent.News

What's breaking now, across thousands of outlets.

AI

금융권 해킹 사태 불과 2주 전…금융보안원 ‘AI 에이전트 공격’ 경고

Just two weeks ago, a hacking incident targeting South Korean financial institutions came to a head. In a warning to the sector, the Financial Safety Authority (FSA) shared real-life examples of AI-powered attacks on financial firms. Despite the warning, similar incidents occurred, leading to criticisms that financial institutions failed to adequately prepare for such threats.

According to a report received on the 11th by lawmaker Han Ching-min of the Democratic Party, the FSA held a seminar on "Responses to Financial AI Security Threats" on the 17th of the previous month, inviting 160+ senior financial officials from seven financial firms that had recently suffered breaches. Excluding three major banks - BNK (Bank of National Trade & Industry) in Busan, KB (Korea Bank), and Hanafinance (Hanafinance) - which were also breached, the attendees included representatives from KB (Korea Bank), HanFinance, Shinhan Capital, WELCOM Savings Bank, and Shinhan Financial Group, where the hacking occurred.

The attackers utilized a Chinese AI model, Deep Stitch, to instruct the AI agent to scan the "oracle web logic" assets of domestic financial institutions. After exploiting vulnerabilities, the hackers installed malicious software, or "web shells," on the servers to gain control. The detected intrusion allowed the financial institutions to block the malicious code, preventing further damage.

This marks the first known instance of AI-powered attacks on South Korean financial institutions. However, it is suggested that earlier identification and containment of the threat could have minimized the impact. Some argue that financial institutions need to review their security decision-making structures following this incident.

Furthermore, the chairman of the Faculty of Information Security at Kyung Hee University, Park Guk-young, emphasized that while appointing a security officer to the board is a step in the right direction, it is crucial that these individuals have the authority and necessary budget to make a real difference in the company's security measures.

Written by urgent.news from Hankyoreh's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at hani.co.kr →

More in AI

I built Chloe: an open-source TypeScript framework for AI agents you control

I built Chloe for developers who want to build AI agents for businesses, especially small businesses. The idea is simple: use code for predictable tasks, and use AI where you need it.

  • I developed Chloe, an open-source TypeScript framework for AI agents.
  • Framework uses code for predictable tasks and AI for necessary operations.
  • Chloe provides developers control over agents, maintaining ownership of code.

Engram Corruption: What Happens When a Skill Container Doesn't Own Its Payload

The setup In a modular AI framework like LivinGrimoire, behavior comes from small, swappable units called skills. A Brain holds them in lobes, and a skill's input() runs on every think cycle.

  • Skills are managed by higher-level AH skills, which handle skill management.
  • Engram snapshot process inadvertently includes payload skills, causing duplication issues.

Google Ads in Claude, with an approve button

I built Camberstack , a hosted MCP server that connects Google Ads to Claude (and ChatGPT, Cursor, or any MCP client). This post is the setup and a real example of using it, so you can decide whether…

  • Camberstack connects Google Ads to Claude for AI-powered ad management
  • Claude requires approval for every change before applying to Google Ads
  • Claude can build and pause Search campaigns within Google Ads

More from Sunday 11 October →