[Photo: SK Shieldus]

SK Shieldus on Wednesday released a report titled "In the era of AI automated attacks, analysis and response guide to breaches targeting Shadow IT" that analyses shadow IT and API security issues that have emerged as major security threats as AI automated attacks spread.

The company said the guide analyses how AI-based attack tools are used and actual intrusion paths, based on recent financial sector breach cases. It also includes information on security systems companies need to prepare for similar attacks.

SK Shieldus assessed that, based on circumstances disclosed so far, recent incidents in the financial sector were closer to cases of automating and advancing existing attacks than cases in which AI created new attack techniques.

Attackers targeted externally exposed assets in management blind spots first, such as loan broker systems, employee support services and sales support platforms, rather than core financial transaction systems. It assessed that AI played a role in searching them faster and at larger scale.

SK Shieldus also noted that when AI-based automated attack tools are used, they can simultaneously scan multiple financial institutions' internet-exposed assets and APIs. It said they can also quickly expand targets based on API call patterns and response information.

It also warned that in environments where key corporate operations are connected through APIs, AI can mimic normal call patterns and conduct large-scale scanning and information gathering, increasing the threat.

SK Shieldus also shared the operating principles and risks of ARTEX, an AI-based penetration testing tool that has been raised as a possible tool used in the attacks, in the guide. SK Shieldus' white-hat hacking organisation EQST (Experts, Qualified Security Team) also released the results of its analysis of ARTEX.

According to EQST, ARTEX is an open-source autonomous penetration testing platform that automates with AI the penetration testing procedures previously carried out by humans. Unlike simple automated scanning tools, it can select the next target to explore on its own based on previous results and expand attack paths.

SK Shieldus said this structure greatly expanded attack speed and scope by automating attacker reconnaissance, vulnerability discovery and verification. The company said that, based on publicly available information and tool analysis results, attackers may have used publicly available AI-based penetration testing tools to probe internet-exposed services and APIs at multiple financial firms via rented servers (VPS) in several countries.

SK Shieldus also stressed that while AI-based attacks are spreading, the essence of security and response principles do not change. It said controls are needed across the entire zero-trust domain, starting with protection of externally exposed assets and APIs, including Identity (users and identity), Device (devices and endpoints), Network, Application (applications and workloads), Data and Visibility (visibility, analysis and automation).

Kim Byung-moo (김병무), head of SK Shieldus' cyber business division and a vice president, said, "AI is not a technology that creates new vulnerabilities but a tool that amplifies attacks, so companies must secure visibility over the assets they hold and strengthen controls over externally exposed areas including APIs." He added, "As the essence of security does not change even in the AI era, we will continue to support customers in building practical security services and zero-trust-based security systems so they can effectively respond to a changing threat environment."

Keyword

#SK Shieldus #Shadow IT #API #ARTEX #EQST
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.