📅 Thursday, 8 October 2026 · --:-- UTC Follow us
Ecosystem ▼
ID EN
Jendela Tambal Celah Bank Susut Jadi Hitungan Menit - AI Temukan 10.000 Titik Lemah

Bank Patching Window Shrinks to Minutes - AI Finds 10,000 Vulnerabilities

The Bank for International Settlements (BIS) has warned that artificial intelligence is now capable of turning software security flaws into active exploits within minutes. A process that once took weeks has shrunk drastically, according to a BIS Financial Stability Institute paper dated Sept. 9, 2026.

The ability of language models to compromise systems was demonstrated in the ExploitGym benchmark. Out of 898 tested cases, the Claude Mythos Preview model crafted active exploits for 157 cases, accounting for 17% of the total tests. Rival model GPT-5.5 followed with exploits in 120 cases, or about 13%. The paper’s authors cautioned that success in a test environment does not automatically mean AI can breach tightly protected banks.

In real-world environments, a report from Anthropic underscored the scale of the threat. Claude Mythos Preview identified more than 10,000 serious vulnerabilities across operational systems. Given that developers have yet to patch over 99% of the flaws, Anthropic restricted the details disclosed to the public. Since April 2026, leaders from several financial institutions and government agencies have begun testing the model to trace system weaknesses prior to its wider release.

Regulators Respond to Third-Party Risks

The primary bottleneck for banks currently lies in response times. The UK Financial Conduct Authority noted that financial firms are struggling to keep pace with the discovery rate of new vulnerabilities. The Verizon Business 2026 Breach Report confirmed this defensive lag: software vulnerability exploitation accounted for 31% of initial access pathways in cyber incidents, surpassing the 13% share from credential theft. Of all evaluated organizations, only 26% remediated their vulnerabilities completely.

This wave of vulnerabilities has prompted authorities to update the rulebook. Four U.S. federal regulators proposed new supervisory guidance on Sept. 11, 2026, targeting third-party technology providers. Months earlier in May 2026, the New York Department of Financial Services issued a circular highlighting AI advancements as a game-changer for the cyber risk landscape of financial institutions.

A Boardroom Matter, Not Just for Technical Teams

The BIS paper emphasized that handling cyber threats is no longer viable when delegated solely to technical teams. Senior management is now expected to help oversee security responses directly from the top. Boards of directors need threat intelligence pipelines and decision-making workflows that trigger remediation execution without being hindered by monthly review schedules.

The speed at which AI identifies cracking points is forcing bank executives to rethink their institutions’ defensive architecture. If boards continue to rely on quarterly meetings to approve system patches, hackers might clear out the vaults before the meeting agenda is even distributed.

Reported via crypto.news.

Read also: US Seizes $52M in Crypto from Xinbi - Network Processed $24B in Scam Money


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
📩 KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share