התחברות ל-baba News

חשבון אחד לאתר, לאייפון ולאנדרואיד — המנוי נשאר איתכם.

או קוד במייל

Welcome — one more step

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. תנאי המנוי.

המנוי פותח גם את האפליקציה.

Search stories

הקלידו לפחות שני תווים. התוצאות מגיעות מכל המערכות ש-baba קורא.

to move · to open · esc to close

מסוף חי

התחברות ל-baba News

Sign in to keep asking. News Plus removes the daily limit.

או קוד במייל

לראות את התמונה המלאה

News Plus opens the cross-newsroom layer — who covered a story, who didn’t, and how each one worded it.

  • Ask Duki without the monthly limit — answers from the coverage, with sources
  • Save articles, synced between the web and the app
  • How each newsroom worded the same event
  • Filing timeline and coverage breakdown
  • The whole archive, searchable
  • Unlimited newsroom, topic and people follows
  • The daily brief by email, in English or Hebrew

Eligible new subscribers get 7 days free, then $34.99 each year. Renews automatically until cancelled. Cancel any time in your account. תנאי המנוי.

המנוי פותח גם את האפליקציה.

ביטחון10:12 · Jul 31

Security Flaw in Financial App Using AI Model Claude Exposes Sensitive Data

מאת אבישי לוי
תורגם ותומצת מתוך Srugim על ידי baba
Security Flaw in Financial App Using AI Model Claude Exposes Sensitive Data
איור מערכת שנוצר על ידי baba News, לא צילום של האירוע.
The story · English

A critical security vulnerability was discovered in a financial application whose significant code was written using the AI model Claude. The flaw was uncovered during a penetration test conducted by the Israeli cybersecurity firm Sigania for a financial institution managing assets worth billions of dollars. The app, designed to onboard new clients and allow users to resume registration before choosing a username and password, relied on a unique GUID to identify returning users. However, the access mechanism issued tokens based solely on possession of the GUID, without verifying the requester’s identity, enabling minimal-permission users who guessed or obtained another user’s GUID to access sensitive information.

Exposed data included personal identifiers such as US Social Security numbers, contact details, credit request statuses, and information about financial partners or joint applicants. Sigania explained this was not a typical programming error but a logical flaw in the authorization design, where the system incorrectly assumed possession of an identifier equated to ownership or permission. Zack Mead, a senior penetration tester at Sigania, noted that automated code scanning tools often fail to detect such vulnerabilities because they stem from trust boundary design rather than explicit code defects.

Ironically, the researchers also used a language model to analyze parts of the code and locate the flaw, highlighting how AI tools that accelerate code writing can also aid security researchers and attackers in quickly identifying weaknesses. Sigania described this phenomenon as the "democratization of vulnerabilities," where even individuals without advanced cybersecurity knowledge can analyze leaked or exposed code using language models to find potential exploits.

While AI-assisted coding does not inherently produce insecure code, risks increase when organizations integrate AI-generated code without thorough human review, architectural assessment, and security testing focused on business logic. This case underscores ongoing cybersecurity debates about uncontrolled AI tool usage within organizations, including unauthorized employee use that may expose internal data and increase leak and attack risks.

In response to rising AI adoption, Sigania announced expanded services for AI system security, including infrastructure and data flow assessments, penetration testing of AI-based applications, and organizational policy development for AI tool usage. Ilia Rabinovich, Sigania’s Cyber Consulting VP, emphasized that organizations must now identify where AI is already in use, what data it accesses, and whether existing security measures address the new risks posed.

Read the original at Srugim
פתיחת המסוף החי