Frontier AI and Identity Security in Financial Services #AI


An AI model just cracked a 29-year-old bug in Squid, the proxy software running schools, ISPs, and corporate networks everywhere. Unit 42 turned two years of pen testing into three weeks using the same tech. Its verdict, from researcher Matt Brady: organizations are “somewhere between three and five months away from these frontier AI models being weaponized.”

The bigger risk for banks isn’t code but identity. Machine identities now outnumber humans 109 to 1, and identity weakness drove nearly 90% of Unit 42’s incident-response cases last year. As Palo Alto’s Paul Leonhirth puts it, “zero trust is the lack of implicit trust.” And most banks still have plenty of it.

So what does this mean for identity and AI governance? Download this Q&A to learn why:

  • AI just shortened the vulnerability-discovery timeline from years to weeks. Unit 42 compressed two years of pen testing into about three weeks using frontier AI models.
  • Weaponization is coming fast. Unit 42 estimates attackers are three to five months away from turning frontier AI models offensive.
  • Identity, not code, is the real attack surface. Nearly 90% of the incidents Unit 42 responded to last year traced back to identity weakness.
  • Machine identities have quietly taken over. Non-human identities now outnumber humans 109 to 1 , with the gap is growing.
  • AI-enabled fraud is on pace to triple. One estimate puts losses at USD40 billion by 2027, up from about USD12 billion in 2023.
  • Most banks are defending with too many tools. Financial institutions run 114 security tools on average, creating blind spots, not protection.



Click Here For The Original Source.

——————————————————–

..........

.

.