Leading edge AI accelerates vulnerability exploitation, shortening the window for bank software repair to minutes
According to a recent report released by the Bank for International Settlements (BIS), advances in cutting-edge artificial intelligence technology are significantly reducing banks 'efforts. The window of time to repair before attackers exploit software vulnerabilities.
The report, released by the Financial Stability Institute on Wednesday, further confirms recent warnings from AI developers and financial regulators that the speed of cyberattacks is accelerating as the capabilities of AI models continue to increase. The new report focuses on banks 'responsiveness, and the authors believe that financial institutions must also speed up the deployment of software patches and the decision-making processes needed to authorize those patches.
From "weeks" to "minutes": security assessment model faces failure
The author wrote in the report: "The most significant development brought about by cutting-edge AI is autonomous vulnerability discovery and exploitation." They warn that traditional regular safety assessments and planned fixes are becoming increasingly inadequate. "The time window between when a vulnerability is discovered and when it is actually exploited has been shortened from weeks to minutes."
The report cited a review by the UK's Financial Conduct Authority (FCA), stating that the rate at which vulnerabilities are discovered has exceeded companies 'ability to respond. At the same time, the Institute of International Finance (IIF) has also issued guidance urging agencies to speed up patch deployment-even if it exceeds planned maintenance windows, and planned downtime should be more widely accepted.
In addition, the report mentioned that voluntary guidance issued by the UK Cross-Market Business Resilience Group predicts that the repair time will be shortened from weeks to days, and in some cases even just hours.
Global regulators are pressing for greater response speed and resilience
Although the timetable mentioned in the report is voluntary, regulators are pushing banks to take faster action. According to the report, the German Federal Financial Supervisory Authority (BaFin) called for accelerated patch deployment, while the Hong Kong Monetary Authority urged enhanced breach response and resilience.
The report states: "For example, the Hong Kong Monetary Authority encourages institutions to integrate AI-based network scenarios into business resilience plans and improve event response and recovery capabilities, recognizing that as the cyber threat environment continues to evolve, the likelihood of 'breakthrough' scenarios occurring is increasing."
The report added: "Similarly, the European Central Bank's (ECB) network resilience stress testing program and the implementation of the Digital Operations Resilience Act (DORA) emphasize that institutions must not only be able to withstand cyber attacks, but also be able to continue to provide critical services during periods of severe business disruption."
Open source case warning: unexpected risks of AI tools
This warning follows a call to strengthen cyber defenses jointly launched in August this year by more than 100 organizations including OpenAI and Anthropic. The signatories recommend stricter access controls, threat information sharing, and closer supervision of AI agents.
The BIS report cited the Hugging Face intrusion incident (involving the OpenAI model) as an example as preliminary evidence that the capabilities demonstrated in testing can be transformed into attacks on real systems. Later, OpenAI described how its agents coordinated their efforts in the operation.
Although the authors caution to point out that normal security measures have been relaxed and a large amount of computing resources have been provided during that incident, they say the incident does not directly reflect the risks posed by publicly available AI tools.
The author wrote: "The OpenAI incident does not indicate that cutting-edge AI models can autonomously generate malicious targets. However, they may pursue a narrowly defined task with unintended and harmful consequences."
"The significance of this development for network resilience is to combine a capable model with surrounding software systems that allow it to plan, use tools, and act autonomously."

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following