Back to News
SecurityAI Understanding briefing

ChosunBiz reports Microsoft security executive says AI could shift cyber defense toward defenders

Microsoft security executive Kim Tae-su told ChosunBiz that AI could help defenders examine vulnerabilities at scale, while describing Microsoft’s MDASH system and urging South Korea to strengthen its cybersecurity industry.

By 5 min readRead the primary source
Source-provided image accompanying ChosunBiz reports Microsoft security executive says AI could shift cyber defense toward defenders
The short version

Microsoft security executive Kim Tae-su told ChosunBiz that AI could help defenders examine vulnerabilities at scale, while describing Microsoft’s MDASH system and urging South Korea to strengthen its cybersecurity industry.

What happened

ChosunBiz reported that Kim Tae-su, Microsoft’s corporate vice president for security, believes AI could eventually reverse the traditional advantage held by cyber attackers. Kim also described MDASH, an AI-based vulnerability detection system that the article says is mandatory in Microsoft Windows’ development pipeline and uses more than 100 specialized sub-agents.

ChosunBiz reported that Kim Tae-su made the comments in an interview on Aug. 26, after delivering a keynote at SMARTCLOUD SHOW 2026 in Seoul. Kim argued that attackers historically needed to find only one exploitable weakness, while defenders had to account for many possibilities. According to ChosunBiz, he said advances in AI could make it realistically possible for defenders to examine those possibilities before attacks occur. He also acknowledged that attackers are currently adopting AI quickly, while defenders face regulation, compliance and cost constraints.

The article says Kim described MDASH as a system that combines multiple AI agents by work stage and role. It reportedly first builds a threat model from software architecture and historical vulnerability information. More than 100 sub-agents then search for weaknesses. Agents assigned hacker, developer and defender roles cross-check the findings, generate proof-of-concept code to test whether an attack is feasible, and produce patches intended to fix the underlying issue. ChosunBiz reported that MDASH uses different AI models for some roles to reduce the chance that the same model will reproduce the same bias.

According to the report, unresolved disagreements are handled through a vote by three models, with a vulnerability reported only when at least two models classify it as a real bug. ChosunBiz said the system is currently used in the Microsoft Windows organization’s continuous integration and continuous delivery pipeline and is mandatory in the development process. The article reported that, within four months of adoption, MDASH found vulnerabilities equivalent to 66% of all vulnerabilities discovered in Windows during the previous year.

That performance claim is not independently confirmed in the supplied source. ChosunBiz did not provide a public technical paper, audit, vulnerability list, test protocol, false-positive rate, or independent assessment of the 66% comparison. The article also said MDASH was commercialized quickly and that many companies in South Korea and abroad were adopting it, but it did not name those companies or provide adoption figures. Kim’s background, including his leadership of Team Atlanta in the 2025 DARPA AI Cyber Challenge, was also reported by ChosunBiz; the supplied source does not independently document those credentials.

Source details: biz.chosun.com

Why it matters

The report presents a concrete example of AI being used in software security workflows, including vulnerability discovery, cross-checking, proof-of-concept generation and patch development. If the reported deployment and results are independently substantiated, the system could affect how large software organizations allocate security testing and engineering resources.

The report matters because it describes AI as an active component of defensive software security rather than as a general productivity tool. MDASH is presented as operating across several stages of the vulnerability process: modeling threats, searching code, testing exploitability and proposing patches. That workflow could be consequential if it consistently identifies complex flaws that conventional testing misses and if human security engineers can safely review its outputs.

Kim’s central argument is broader than the product description. ChosunBiz reported that he expects AI to narrow the asymmetry between attackers and defenders because defenders control the code-release process and can examine systems before deployment. That is a forecast and an executive’s assessment, not evidence that the balance has already shifted across the cybersecurity sector. The article itself says Kim believes attackers currently retain an advantage because defensive organizations face additional legal, compliance and spending constraints.

The report also connects AI security tools to South Korea’s industrial policy. Kim told ChosunBiz that Korea has highly capable security workers but lacks an industrial base that sufficiently supports them. He cited lower pay for security personnel than for general software developers and said Korean specialists often seek opportunities abroad. Those comments identify workforce retention and compensation as practical constraints, although the article does not provide labor-market data to measure the claimed wage gap or migration.

Kim further warned that AI could replace some junior security work while increasing demand for people who understand AI, software development and security together. That possibility has public significance because entry-level security tasks can provide training and a pathway into the profession. Whether AI removes those opportunities, changes them, or creates new ones cannot be determined from this interview. The report offers no workforce study, employment figures or evidence that MDASH has already changed staffing at Microsoft or elsewhere.

What to watch next

The key questions are whether Microsoft publishes evidence supporting MDASH’s reported performance, how the system performs outside Windows, and whether it reduces missed vulnerabilities without creating excessive false positives or new risks. The broader workforce effects described by Kim also remain uncertain.

The first priority is independent verification of MDASH’s reported results. Useful evidence would include Microsoft technical documentation, a peer-reviewed or independently reviewed evaluation, representative vulnerability records, and clear definitions of what “equivalent to 66%” means. Observers would also need to know how many findings were confirmed, how many were duplicates or false positives, how patches were tested, and whether the system found flaws that human teams or existing automated tools had missed.

The system’s use of proof-of-concept code deserves particular scrutiny. ChosunBiz reported that MDASH generates such code to verify attack feasibility, but the source does not explain what safeguards isolate those tests, prevent accidental exploitation, or control access to generated material. Future reporting should examine whether the workflow operates only in authorized environments and how Microsoft handles proof-of-concept artifacts that could be repurposed.

The scale and durability of deployment are also unknown. ChosunBiz said MDASH is mandatory in the Windows development process and that many other corporations are adopting it, but gave no dates for broader rollout, customer names, pricing, deployment requirements or evidence from outside Microsoft. Confirmation of use across independent organizations would help distinguish a company-specific engineering program from a more general change in commercial cybersecurity practice.

Finally, the workforce and strategic claims need evidence beyond Kim’s assessment. South Korea’s government, universities and security companies could clarify whether compensation, training and retention are changing, and whether AI is expanding or narrowing entry-level roles. More broadly, future evaluations should test whether AI-assisted defense improves real-world resilience without giving attackers comparable advantages. The supplied source establishes that a senior Microsoft security executive made these claims and described a deployed system; it does not establish that AI has already given defenders the upper hand.

Related guides & quizzes

AI AgentsAI Models ExplainedAI EthicsAI TrainingTest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?