que paso
Chosunbiz reported that Cloudflare executives speaking at a media education session in Seoul warned that AI agents are generating rapidly increasing network traffic and expanding the number of services that companies must secure. The executives urged organizations to identify internal AI tools, limit access by identity and permission, control unapproved MCP connections and protect sensitive information sent in prompts. Cloudflare also discussed AI-assisted cyberattacks and its planned expansion of post-quantum authentication support.
Chosunbiz reported that Goran Risticsevich, Cloudflare’s executive vice president and managing director for Asia-Pacific, said AI-agent traffic on Cloudflare’s network had increased by more than 1,700% from a year earlier and represented about 60% of all network traffic. The article did not provide the underlying baseline, the precise measurement period, the geographic scope of the figures, the definition of AI-agent traffic or an independent source for the estimates. Those omissions make the scale of the increase difficult to evaluate, even though the claims were presented as the central evidence for Cloudflare’s warning.
Chosunbiz reported that Risticsevich contrasted ordinary human browsing with agents that can connect to many websites and servers at once. The article said this creates a larger security-management problem because companies need to know which AI system is accessing which data and systems, and whether that access is necessary. The report also described shadow AI, in which employees use unapproved AI services and may send sensitive internal information to external models. It identified shadow MCP as a related risk involving unapproved Model Context Protocol connections to external tools or internal systems.
Cloudflare told Chosunbiz that companies should first identify the AI tools being used internally and then control their data and network access. The company recommended blocking prompts that contain sensitive information and applying zero-trust principles to MCP-server access, so that users can reach only the applications allowed by their identities and permissions. These recommendations were presented as Cloudflare’s guidance, not as the result of an independently reported regulatory standard, customer study or controlled evaluation. The article did not identify specific organizations that had suffered a shadow-AI or shadow-MCP incident.
The report also covered Cloudflare’s participation in Project Glasswing, a security consortium conducted with Anthropic. Chosunbiz reported that Cloudflare received early access to Anthropic’s Mythos AI model for testing by its internal security team, and that Cloudflare said the tests showed AI had become more capable of chaining multiple vulnerabilities and was finding new vulnerabilities faster. The article provided no test design, comparison group, measured results or independent validation. Cloudflare executives argued that organizations cannot rely solely on applying patches one vulnerability at a time and should strengthen broader security controls.
Lea la fuente principal: biz.chosun.com ↗
Por qué es importante
AI agents can interact with many external websites, tools and internal systems on a user’s behalf, creating security and data-governance risks that differ from those of ordinary software users. The report offers practical concerns around shadow AI, shadow MCP and vulnerability chaining, but its most significant statistics and test results are Cloudflare claims reported by Chosunbiz and were not independently confirmed.
The practical significance of the report is that AI agents can expand the number and speed of interactions between a company’s employees, models, tools and data stores. A conventional application may have a defined set of permissions and destinations, while an agent can select tools or services dynamically within the authority it receives. If those permissions are too broad, a compromised agent, malicious instruction or poorly governed integration could expose information or trigger actions beyond what the user intended. Chosunbiz’s account supports the need for tighter governance, but it does not establish how often these failures are occurring.
Shadow AI is a familiar enterprise problem, but the report suggests that MCP can make it more operationally significant by connecting models to systems that can retrieve information or perform actions. An unapproved connection could create risks even when the model itself is not the source of the problem. The article’s emphasis on identity-based access and least privilege is therefore relevant to companies adopting agentic tools. However, Chosunbiz did not report independent evidence that shadow MCP is already widespread in South Korea or quantify the losses caused by it.
The cybersecurity claims also matter because AI may affect both sides of the defense cycle. Cloudflare’s account, as reported by Chosunbiz, describes AI systems as becoming better at linking vulnerabilities into attack paths and moving faster in vulnerability discovery. If independently confirmed, that would increase pressure on defenders to automate asset inventory, detection, prioritization and response. Yet the source provides no technical details about the Mythos tests and no evidence that the reported findings translate into successful attacks against real organizations. The claim should therefore be treated as a warning from a security company, not as a verified measure of current criminal capability.
The post-quantum issue adds a longer-term infrastructure concern. Chosunbiz reported that Cloudflare supports quantum-resistant encryption and expects to provide full quantum-resistant authentication by 2028, while one executive said the industry expects a possible Q Day around 2030. Migration away from vulnerable cryptographic systems can take years because certificates, protocols, devices and third-party services must be inventoried and upgraded. The report does not establish that those dates are consensus forecasts, nor does it explain the scope of Cloudflare’s current support. The public value is in highlighting migration planning, not in treating the dates as predictions.
Qué ver a continuación
The main questions are whether Cloudflare’s traffic estimates can be independently documented, how much of the reported activity represents useful agent work rather than automated requests, and whether the company’s security recommendations produce measurable reductions in unauthorized access or data leakage. Cloudflare’s stated plan to fully support quantum-resistant authentication by 2028 is also a future commitment rather than a completed deployment.
First, independent measurement is needed for Cloudflare’s traffic claims. Useful follow-up reporting would identify what Cloudflare counts as an AI agent, whether the 1,700% increase compares equivalent periods, whether the 60% figure applies globally or to a particular segment, and how crawler, search, inference and autonomous-agent traffic are separated. Without that information, the statistics show Cloudflare’s assessment but cannot reliably describe the entire internet or South Korean networks.
Second, companies adopting agentic systems should disclose how they inventory model and tool use, approve MCP servers, restrict permissions and prevent sensitive prompt data from leaving controlled environments. The report gives no evidence that Cloudflare’s proposed controls have been independently tested. Follow-up evidence should include real deployment results, documented incidents, audit findings or comparative evaluations showing whether zero-trust controls reduce unauthorized tool calls, data exposure or harmful actions.
Third, the Project Glasswing claims warrant technical scrutiny. Chosunbiz’s report does not say which vulnerabilities were chained, how the model was prompted, whether the tests used realistic environments, how performance compared with existing tools or whether Anthropic independently agreed with Cloudflare’s interpretation. Independent researchers and defenders should look for reproducible methods and publicly described results before drawing conclusions about the pace of AI-enabled vulnerability discovery.
Finally, Cloudflare’s post-quantum timeline should be tracked as a product and migration commitment. Follow-up reporting can clarify which encryption features are already available, what full quantum-resistant authentication will cover, and whether customers must change certificates, software or hardware. The source also leaves unresolved whether the reported AI-agent traffic surge is concentrated among a small number of large services or reflects broad adoption. Those unknowns are central to judging both the urgency and the public impact of Cloudflare’s warning.


