Search
Choose a style
Dark
Light
Time to read: 4 min

Payment Expert Summit: Vulnerability reports up tenfold since the AI boom

Payment Expert Summit: Cyber threat
Payment Expert Summit

AI has multiplied real vulnerabilities and cut the cost of finding them. Three security specialists set out what operators now face.

A hacker can now rent an AI tool for $200 a month and have it surface zero-day vulnerabilities in minutes. A company’s defence against those same flaws runs into the millions. 

Jay Balan, Super Technologies
Jay Balan, Super Technologies. Image credit: LinkedIn

It is increasingly becoming cheaper to attack, and more expensive to maintain rigorous defenses, which was the throughline for most of what was said at the “Cyber Under Attack: Staying Ahead of the Next Threat” panel.

Jay Balan has spent more than two decades in cybersecurity and vulnerability research, the last five running security for Super Technologies. Lyubomyr Pavlyk built his career across consultancy, crypto and blockchain security before co-founding NisAI. 

Rahul Das of Spyglass Insights moderated, and opened by framing the problem innovations introduced by operators have invariably caused; every API, every automation, every third-party integration adds reach, and every bit of reach represents another vector from which fraudsters can attack.

Finding vulnerability in defence was never the problem for AI to solve

The industry instinct, an audience member suggested, was to treat it as a crisis. Balan noted though that finding vulnerabilities  was never where the difficulty lay – and AI has only made that more true. 

“The major hurdle to overcome is service level agreements (SLAs) with your engineers to fix the vulnerabilities, not finding,” he said. 

You can point any model you like at your own code and watch the list of holes grow. He described what costs time and money is everything after, from validating what the tool spits out, to ruling out the false positives, and redesigning systems so a confirmed flaw can be fixed before someone exploits it.

Lyubomyr Pavlyk, NisAI
Lyubomyr Pavlyk, NisAI. Image credit: LinkedIn

His argument reframes the AI panic, as the same tooling sits on both sides of the attack vs defence divide.

“There is no such situation the AI is only helping bad actors,” Pavlyk said. Defenders get the acceleration too; the attacks simply come faster and more often, because, as he put it, AI never sleeps.

Balan suggested AI could help shrink the attack surface, not grow it – if operators use it for what he describes as the “unglamorous work.” 

Most companies run thousands of slightly different versions of the same building blocks: dozens of secure socket layer (SSL) libraries, countless Docker images, web servers patched to no consistent standard. He said if this was standardised onto common components, any new vulnerability no longer means touching ten thousand places. 

The rules protect the attacker

The issue for operators is on the limits of the defences operators already trust. Fraud systems flag a login from a new IP address followed by a change of payment method; which is reasonable enough. But Balan’s point was the same rules work for the other side. “Thresholds and rules are actually loved by hackers because a rule and a threshold is a marker – they know it,” he said.

Define a limit and you have told the attacker exactly where to stay beneath it, where they can spread nefarious activity across multiple identities and devices and sliding under the bar you set.

His working assumption is to always assume a breach has already happened and build from there. 

The real danger in stored customer data, he said, is not account theft but blackmail – attackers who hold the records hostage against a slice of company value. 

His advice to operators was to say if regulators force you to keep the original data, it’s best  to lock the copy on a machine nobody touches, wall it off, and run everything you need off anonymised versions.

Subscribe to our newsletter