AI tools are being used in a string of cyberattacks targeting the financial sector, prompting the industry to present various alternatives. Cyber resilience company Piolink emphasised a multilayer defense system that combines proactive risk management through continuous threat exposure management (CTEM), real-time attack blocking through web application firewalls and 24-hour security monitoring.
CTEM goes beyond one-off checks of a company’s IT assets and vulnerabilities, the company said. It continuously identifies externally exposed attack surfaces, verifies the likelihood of actual attacks and supports setting response priorities.
Piolink’s AI agent-based cyber threat management platform BlueHunter implements this CTEM framework by combining attack surface management with AI-based penetration verification. BlueHunter searches and analyses internet-exposed assets and vulnerabilities, and AI designs attack scenarios to verify whether they can be exploited.
This allows security managers to identify items with a high real risk of attack and respond first, rather than managing numerous vulnerabilities in the same way, the company said. It said real-time blocking is important in web and API sections where actual attacks enter, and Piolink is responding through its WebFront-K web application firewall.
Piolink said it is providing users with WebFront-K signatures that respond to attacks related to ARTEX, an AI penetration testing tool used in recent attacks on South Korea’s financial sector. It said this enables detection and blocking of attack requests that match the signatures.
It added that the system can respond to various web attacks such as SQL injection and cross-site scripting (XSS), as well as automated account attacks such as credential stuffing, abnormal web and API requests and attempts to exploit vulnerabilities.
Piolink said, "AI-based attack tools can combine various attack methods, so a single security product cannot defend against all attacks." It said bypass attacks involving authentication and authorisation using normal request formats, or attacks that exploit business logic, must be addressed alongside security controls in applications. It also said that in an environment where AI-based attacks are automated and repeated, security operations capabilities that continuously analyse signs of attack and respond are important as well as adopting security solutions.
Piolink CEO Young-chul Cho (조영철) said, "As AI accelerates vulnerability discovery and penetration attempts, companies must establish a system that finds and verifies risks before attacks occur, blocks actual attacks quickly, and continuously monitors and responds to threats." He said, "Piolink will support customers’ responses to cyber threats and help secure business continuity through AI-based CTEM, web application firewalls with intelligent web and API security functions, and professional security monitoring services."