"601 White-Hat Hackers Join Forces"—Financial Security Institute Strengthens Joint Response with 178 Financial Firms
- Input
- 2026-09-21 14:46:28
- Updated
- 2026-09-21 14:46:28

On the 21st, the Financial Security Institute said it had identified 1,316 vulnerabilities through the Financial Sector Software Supply Chain Security Platform, which is currently in operation. It said the public and private sectors had jointly established a coordinated response system against increasingly widespread cyberattacks using artificial intelligence (AI).
The Financial Security Institute asked financial companies participating in the platform to respond to the identified vulnerabilities. As the use of AI spreads, the volume and speed of vulnerability discovery have increased rapidly. Some large financial companies with AI response capabilities can apply patches and strengthen security immediately after vulnerabilities are discovered. However, some smaller financial companies lack the capabilities and funding not only to identify vulnerabilities but also to address them promptly.
According to the Financial Security Institute, recent cyberattacks have expanded beyond direct attacks on financial companies to targeting vulnerabilities in software supply chains, including commercial software and open-source software commonly used by financial companies. The risk of cyberattacks is growing further because a vulnerability in a single software program can affect multiple financial companies using the same software. The institute explained that individual financial companies' own responses have limitations because fundamental remediation depends on patches from software developers.
The Financial Security Institute has strengthened cooperation at each stage, from vulnerability discovery through patching and remediation, via a platform involving 601 white-hat hackers and 31 software developers. The number of vulnerability reports submitted by white-hat hackers has approximately doubled from the previous year, while requests for patch development have increased 5.7-fold.
The Financial Security Institute also provides Software Bill of Materials (SBOM) management functionality, allowing users to check in advance whether software components, including open-source software, contain vulnerabilities. An SBOM is a type of specification listing open-source software, libraries and other components that make up software, along with their version information. The functionality is currently being used in 55 projects. Approximately 350,000 domestic and international Common Vulnerabilities and Exposures (CVE) records are linked to SBOMs, helping users verify security before software is developed, adopted or distributed and quickly assess the impact of newly discovered vulnerabilities during operation. CVE is a reference system for identifying vulnerabilities and exposures discovered in software or systems. A security vulnerability is a flaw in software code that can allow an attacker to directly access a system or execute malicious code.
The Financial Security Institute plans to continue developing the Financial Sector Software Supply Chain Security Platform in connection with the government's Roadmap for Strengthening Software Supply Chain Security.
Park Sang-won, president of the Financial Security Institute, said, "As the time available to respond between the disclosure of a software vulnerability and its actual exploitation is growing shorter, it is becoming increasingly important not only to discover vulnerabilities quickly but also to link that discovery to remediation as swiftly as possible. As vulnerability reports are also rising sharply with the spread of AI, we will manage them comprehensively and address them promptly through a joint response system involving financial companies, white-hat hackers and developers, thereby contributing to a secure electronic financial transaction environment."
[email protected] Park Mun-su Reporter