Why the barrier to attacking payment software is falling

Why the barrier to attacking payment software is falling

Douglas Buan, CISO, Wind River Payments, explains how AI and automation are lowering the technical barriers to attacking payment software, accelerating vulnerability exploitation and making malicious activity harder to distinguish from legitimate automated processes.

For years, attacking payment software took technical skill. An attacker needed to read and write code, understand how an application handled card data and write an exploit that worked. That requirement filtered out most would-be attackers and bought fraud defence teams time. It also made it easier for smaller software vendors to assume they weren’t worth the effort.

That assumption is no longer true. AI and automation can examine code and adapt techniques for less experienced attackers that once required deeper expertise. Providers can no longer rely on an attacker’s lack of skill, manual reconnaissance, or cost of an attack as barriers to entry or to buy time.

Three developments are driving this.

1. Exploit efficiency. AI tools can analyse code, automate exploits or multi-step known exploits, or write new exploits at scale.

2. The time to respond is shrinking. Once a vulnerability is disclosed, attackers automate the search for vulnerable environments. We now see exploitation attempts within 24 hours of disclosure. A provider that waits for its next scheduled release may leave a SaaS app or an affected integration vulnerable.

3. Automated access can conceal an attack. Attacks can be concealed in automation that runs in payment environments. Service accounts give scripts and other automated processes access to payment integrations through processes such as API keys. If an attacker obtains requisite access levels, their activity can look like routine system traffic.

What can security leaders do?

Close the patch window. PCI DSS allows one month from release to install critical security patches. This is not fast enough considering the accelerated pace of attack that AI has enabled. Best practices are now seven days for critical CVEs. Meeting that target takes more resources for vulnerability management and release processes built for speed. Work toward machine speed defence.

Use AI defensively. Frontier AI models should be used for code review or development as part of the CI/CD pipeline. Providers are releasing new tools to assist and automate with this approach.

Govern automated access. Know which service accounts and credentials an integration uses, limit what they can access and monitor for anomalous activity. Incident response plans should be updated to review Non-Human Identity (NHI) and agentic AI activity. Have an agentic kill-chain.

Design for least privilege and zero trust. All users should be configured and reviewed regularly for least privilege. All automated processes should be limited to only that which they need for their specific purpose. This helps limit attacker lateral movement and escalation of privileges.

Don’t skip the basics. Good cyber-hygiene is unglamorous, but it stretches the time between initial access and full compromise even under automated AI exploit attempts. Be consistent and intentional with your vulnerability management programme.

Security leaders can’t control which tools attackers use, but they can control how quickly they identify an exposed system, reduce its risk and contain an intrusion. The organisations that come out ahead will be the ones that match attackers’ speed with faster patching, tighter control of their own automation, and defences built to buy time.

Browse our latest issue

Intelligent CISO

View Magazine Archive