Israeli cyber firm Sygnia exposes vulnerability in AI-generated code

Israeli company Sygnia has identified a critical security breach in a major financial institution's application. The flaw, stemming from code written by the AI model Claude, allowed unauthorized access to sensitive customer data.

Source
Israeli cyber firm Sygnia exposes vulnerability in AI-generated code
Photo: ICE / פריצת אבטחה (צילום shutterstock)

The Israeli cyber company Sygnia has exposed a significant security vulnerability in the application of a large financial institution that manages billions of dollars in assets. According to the company, the source of the failure was code written mostly using the artificial intelligence (AI) model Claude, which created a mechanism allowing unauthorized access to sensitive personal and financial information.

The application was designed to assist customers who stopped the registration process midway, allowing them to return to the point where they left off without needing to create a new username and password. However, according to Sygnia's findings, the authentication mechanism issued access tokens to users based solely on a user ID, without verifying that the requester was indeed the account owner.

As a result of this failure, users with basic permissions could gain access to sensitive information of other customers, including personal identification numbers, credit application details, contact information, and data related to financial partners.

One of the most notable aspects of the incident is what Sygnia calls the "AI paradox":

While one language model helped write the code that led to the vulnerability, the company's researchers used another AI model to analyze the code and identify the failure within minutes.

Sygnia warns that the case illustrates a new reality in the cyber world. According to the company, even someone who is not an information security expert may in the future be able to identify complex weaknesses using AI tools if they have access to the source code. Furthermore, they note that code written using AI may pass standard software tests while still containing significant logical failures that are difficult to identify using traditional security tools.

Following these findings, Sygnia announced the launch of a dedicated security services suite for AI technologies. The new services include resilience assessment for AI systems, penetration testing for AI-based applications, and the development of a management and security framework to help organizations address the growing risks associated with the rapid adoption of this technology.

Related News