Skip to main content

AI agents discovered a problem in Bereke Bank's service interface

Submitted by fbrk_news on
ИИ-агенты обнаружили проблему в служебном интерфейсе Bereke Bank

On the Bereke Bank website, a publicly accessible Laravel Boost service interface was discovered, through which an unauthorised user was able to send a test request to the server. The bank confirmed a configuration flaw in the website, although there is no data on leakage of personal information or financial losses for clients.

HOW THE PROBLEM WAS DISCOVERED

According to BES.media, the service interface was discovered by an Almaty resident, Alisher Akhmetov, who noticed that the Bereke Bank website was running slowly. When checking via the browser's developer tools, he noticed a Browser Logger and MCP server — components related to technical development and interaction with AI tools.

During the check, Akhmetov sent a test message, BEREKE_TEST_12345, and received a response from the website with code 200, which means the request was accepted. After that, he reported the finding to the bank's cybersecurity service, KZ-CERT, the National Bank, the Ministry of Internal Affairs (MVD) and other organisations.

WHAT AI AGENTS HAVE TO DO WITH IT

Laravel Boost is used for interaction between AI agents and Laravel applications and for obtaining technical information related to program code. In this case, the problem arose because the service mechanism was accessible from outside.

According to Akhmetov, via the discovered service address of the website it was possible to send entries to the technical log. He also suggested that specially crafted entries could theoretically be used to influence an AI agent if it reads such logs. At the same time, Akhmetov himself emphasises that he did not test such an attack and did not provide evidence of its feasibility at Bereke Bank.

WHAT RISKS WERE DISCOVERED

During the check, the developer involved in the research drew attention to the possibility of technical logs being automatically transmitted from the website to the server. Such logs could potentially contain users' personal data, especially with verbose debugging mode enabled.

Another possible consequence cited was additional load on the server due to the constant sending of logs. At the same time, there are no facts of personal data leakage or financial losses for clients.

WHAT THE BANK AND KZ-CERT RESPONDED

KZ-CERT told Akhmetov that it had passed information about the publicly accessible Laravel Boost service address to Bereke Bank. According to the researcher, representatives of the bank, during their own check, did not find the test entry he had sent.

At the same time, Bereke Bank's press service confirmed the website configuration flaw. The problem was fixed a little over a day after it was discovered.

Источник
BES.media
Наша редакция участвует в партнёрской сети «Все СМИ».