Korea Internet & Security Agency (KISA): "In the Era of AI-Powered Hacking, Swift Action Matters More Than Finding Vulnerabilities"
- Input
- 2026-09-22 12:00:00
- Updated
- 2026-09-22 12:00:00

In the era of 66,000 vulnerabilities... "Prioritizing risks matters more than finding more vulnerabilities"
Bae Seung-gwon, head of KISA's Vulnerability Management Center, emphasized in a presentation titled "The Current State of Cybersecurity Vulnerabilities and Proactive Response" at KISA Issue & Talk held on the 21st, "If AI is speeding up attacks, the speed of defense must also increase to keep pace."The number of security vulnerabilities disclosed worldwide is rising rapidly. Annual Common Vulnerabilities and Exposures (CVE) disclosures increased from 29,066 in 2023 to 48,185 last year and are expected to reach approximately 66,000 this year. That figure is 46.3% higher than the estimate made at the beginning of the year. KISA identified the spread of AI-based autonomous vulnerability discovery tools as one of the factors driving the increase in vulnerability disclosures.
However, Bae said, "An increase in the number of disclosed vulnerabilities does not mean that software has become more dangerous to the same extent." He added, "What matters is not how many vulnerabilities exist, but how quickly they can be identified and how accurately they can be assessed." He continued, "The key going forward is not to respond to every vulnerability in the same way, but to find and address the vulnerabilities that pose a real threat." He explained that "prioritizing verification and assessment is important."
The problem is the gap between the speed of attacks and that of defense. Of the 884 vulnerabilities exploited in actual attacks last year, 29% were exploited on or before the day they were disclosed. By contrast, it took companies an average of 43 days to patch vulnerabilities, up from 32 days the previous year.
The time required to turn a vulnerability into an actual attack tool is shrinking. KISA introduced an analysis from the cybersecurity industry that the time needed to develop an exploit, which previously took several days to several weeks, could be reduced to several hours with AI and eventually to less than 10 minutes. Bae said, "Because attacks can accelerate after a vulnerability is disclosed, the time available for companies to respond will inevitably shrink." He added, "The challenge for companies is determining how quickly they can identify and address dangerous vulnerabilities."
KISA is also using AI in the defense process. It uses AI to inspect externally accessible webpages of major infrastructure facilities, as well as commercial and open-source software, after which experts verify whether the findings could be used in actual attacks.
During a question-and-answer session, Bae explained, "AI was able to shorten to a brief period the time that it might take a person a week or a month to find vulnerabilities." He added, "More important than the fact that AI found vulnerabilities is establishing a system to verify how many of the results it found are valid and whether there are any false positives." He emphasized, "AI is both an attacker's tool and a defender's tool," adding, "Defenders must also use AI to inspect more assets, prioritize them, take action, and verify the results."

Overseas general-purpose AI has limitations... "Korea-specific security models are needed"
Kim Eun-seong, head of KISA's Threat Response Policy Team, emphasized that "AI for Security," which uses AI for cybersecurity, and "Security for AI," which protects AI itself, must develop together.Kim said, "They have different meanings, but they are two sides of a complementary coin that must advance together." He explained, "AI for Security means deploying AI as a defensive weapon across the broader defense process, including vulnerability detection and automated patch generation." In contrast, Security for AI refers to protecting AI systems themselves from threats such as prompt injection, model theft, and data poisoning.
Kim emphasized the need for a security-focused foundation model tailored to South Korea's environment. He said, "South Korea faces many attacks due to its geopolitical position, and the threat actors also have distinctive characteristics." He added, "Our country's security architecture also differs from that of other countries in areas such as network-segregated environments and the use of HWP, so there are limitations to simply importing and using overseas general-purpose models."
He said the technology gap with global general-purpose AI could be narrowed by focusing on specific fields. Comparing global AI to a "genius" who has studied many disciplines, Kim explained, "It is not easy to catch up with the entire field immediately, but we can catch up by developing one discipline at a time through intensive focus. That is the direction of security-focused foundation models."
Regarding development, he emphasized dividing roles between the government and the private sector. During a question-and-answer session, Kim said, "The government must lead the effort, but it will be difficult without the private sector's technical support." He added, "Private-sector participation is inevitable. The government must lead, while the private sector must drive its expansion."
[email protected] Yoon Hong-jip Reporter