뉴스로 돌아가기
보안AI Understanding 브리핑

ChosunBiz는 Microsoft 보안 임원이 AI가 사이버 방어를 방어자 쪽으로 전환할 수 있다고 보도했습니다.

Microsoft 보안 책임자 김태수는 조선비즈와의 인터뷰에서 AI가 방어자가 대규모로 취약점을 조사하는 데 도움이 될 수 있다고 말하면서 Microsoft의 MDASH 시스템을 설명하고 한국의 사이버 보안 산업 강화를 촉구했습니다.

5 min readRead the original reporting
Source-provided image accompanying ChosunBiz reports Microsoft security executive says AI could shift cyber defense toward defenders
기여 보고녹음된 소스
출판사
biz.chosun.com
소스 링크
biz.chosun.comhttps://biz.chosun.com/en/en-it/2026/08/30/QKQO6EEOCZHY5O5SGHW25OVMD4/?outputType=amp
소스 유형
자사 문서가 아닌 뉴스 매체를 통한 보도입니다.

자체적으로는 확인할 수 없었던 내용: 이 소유권 주장은 해당 매장에 귀속됩니다. 당사는 자사 문서와 비교하여 이를 확인하지 않았습니다. (biz.chosun.com)

맥락60초 안에 이해하세요

여기서 시작하세요

주요 용어

파이프라인
전처리, 모델 단계, 후처리 단계의 순서가 지정된 워크플로우입니다.
편견
데이터 또는 모델 동작의 일관된 오류 또는 불공정 패턴입니다.
자신을 테스트해 보세요AI 에이전트 퀴즈

무슨 일이 일어났나요?

ChosunBiz reported that Kim Tae-su, Microsoft’s corporate vice president for security, believes AI could eventually reverse the traditional advantage held by cyber attackers. Kim also described MDASH, an AI-based vulnerability detection system that the article says is mandatory in Microsoft Windows’ development and uses more than 100 specialized sub-agents.

ChosunBiz reported that Kim Tae-su made the comments in an interview on Aug. 26, after delivering a keynote at SMARTCLOUD SHOW 2026 in Seoul. Kim argued that attackers historically needed to find only one exploitable weakness, while defenders had to account for many possibilities. According to ChosunBiz, he said advances in AI could make it realistically possible for defenders to examine those possibilities before attacks occur. He also acknowledged that attackers are currently adopting AI quickly, while defenders face regulation, compliance and cost constraints.

The article says Kim described MDASH as a system that combines multiple AI agents by work stage and role. It reportedly first builds a threat model from software architecture and historical vulnerability information. More than 100 sub-agents then search for weaknesses. Agents assigned hacker, developer and defender roles cross-check the findings, generate proof-of-concept code to test whether an attack is feasible, and produce patches intended to fix the underlying issue. ChosunBiz reported that MDASH uses different AI models for some roles to reduce the chance that the same model will reproduce the same .

According to the report, unresolved disagreements are handled through a vote by three models, with a vulnerability reported only when at least two models classify it as a real bug. ChosunBiz said the system is currently used in the Microsoft Windows organization’s continuous integration and continuous delivery and is mandatory in the development process. The article reported that, within four months of adoption, MDASH found vulnerabilities equivalent to 66% of all vulnerabilities discovered in Windows during the previous year.

That performance claim is not independently confirmed in the supplied source. ChosunBiz did not provide a public technical paper, audit, vulnerability list, test protocol, false-positive rate, or independent assessment of the 66% comparison. The article also said MDASH was commercialized quickly and that many companies in South Korea and abroad were adopting it, but it did not name those companies or provide adoption figures. Kim’s background, including his leadership of Team Atlanta in the 2025 DARPA AI Cyber Challenge, was also reported by ChosunBiz; the supplied source does not independently document those credentials.

소스 세부정보: biz.chosun.com ↗

왜 중요한가요?

The report presents a concrete example of AI being used in software security workflows, including vulnerability discovery, cross-checking, proof-of-concept generation and patch development. If the reported deployment and results are independently substantiated, the system could affect how large software organizations allocate security testing and engineering resources.

The report matters because it describes AI as an active component of defensive software security rather than as a general productivity tool. MDASH is presented as operating across several stages of the vulnerability process: modeling threats, searching code, testing exploitability and proposing patches. That workflow could be consequential if it consistently identifies complex flaws that conventional testing misses and if human security engineers can safely review its outputs.

Kim’s central argument is broader than the product description. ChosunBiz reported that he expects AI to narrow the asymmetry between attackers and defenders because defenders control the code-release process and can examine systems before deployment. That is a forecast and an executive’s assessment, not evidence that the balance has already shifted across the cybersecurity sector. The article itself says Kim believes attackers currently retain an advantage because defensive organizations face additional legal, compliance and spending constraints.

The report also connects AI security tools to South Korea’s industrial policy. Kim told ChosunBiz that Korea has highly capable security workers but lacks an industrial base that sufficiently supports them. He cited lower pay for security personnel than for general software developers and said Korean specialists often seek opportunities abroad. Those comments identify workforce retention and compensation as practical constraints, although the article does not provide labor-market data to measure the claimed wage gap or migration.

Kim further warned that AI could replace some junior security work while increasing demand for people who understand AI, software development and security together. That possibility has public significance because entry-level security tasks can provide training and a pathway into the profession. Whether AI removes those opportunities, changes them, or creates new ones cannot be determined from this interview. The report offers no workforce study, employment figures or evidence that MDASH has already changed staffing at Microsoft or elsewhere.

Interactive Mechanism

대화형 메커니즘: 실제로 작동하는 방식

이 개발의 이면에 있는 기본 기술을 대화식으로 살펴보세요.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
대화형 개념 확인+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

다음에 무엇을 볼 것인가

The key questions are whether Microsoft publishes evidence supporting MDASH’s reported performance, how the system performs outside Windows, and whether it reduces missed vulnerabilities without creating excessive false positives or new risks. The broader workforce effects described by Kim also remain uncertain.

The first priority is independent verification of MDASH’s reported results. Useful evidence would include Microsoft technical documentation, a peer-reviewed or independently reviewed evaluation, representative vulnerability records, and clear definitions of what “equivalent to 66%” means. Observers would also need to know how many findings were confirmed, how many were duplicates or false positives, how patches were tested, and whether the system found flaws that human teams or existing automated tools had missed.

The system’s use of proof-of-concept code deserves particular scrutiny. ChosunBiz reported that MDASH generates such code to verify attack feasibility, but the source does not explain what safeguards isolate those tests, prevent accidental exploitation, or control access to generated material. Future reporting should examine whether the workflow operates only in authorized environments and how Microsoft handles proof-of-concept artifacts that could be repurposed.

The scale and durability of deployment are also unknown. ChosunBiz said MDASH is mandatory in the Windows development process and that many other corporations are adopting it, but gave no dates for broader rollout, customer names, pricing, deployment requirements or evidence from outside Microsoft. Confirmation of use across independent organizations would help distinguish a company-specific engineering program from a more general change in commercial cybersecurity practice.

Finally, the workforce and strategic claims need evidence beyond Kim’s assessment. South Korea’s government, universities and security companies could clarify whether compensation, training and retention are changing, and whether AI is expanding or narrowing entry-level roles. More broadly, future evaluations should test whether AI-assisted defense improves real-world resilience without giving attackers comparable advantages. The supplied source establishes that a senior Microsoft security executive made these claims and described a deployed system; it does not establish that AI has already given defenders the upper hand.

관련 가이드 및 퀴즈

AI 에이전트AI 모델 설명AI 윤리AI 트레이닝알고 있는 내용을 테스트해 보세요. 무료 AI 퀴즈를 시도해 보세요.용어집에서 AI 용어를 찾아보세요.AI 규제 추적기를 따르세요
이것이 유용하다고 생각하시나요?