Що сталося
The Korea Internet & Security Agency (KISA) has announced an upgrade to its national vulnerability response system, incorporating AI to expedite the identification and remediation of security risks. Since May, KISA has utilized OpenAI’s Government and Institutions Trust Access Control (GTAC) program to assess public web pages of critical infrastructure and major software. According to Seungkwon Bae, head of KISA’s Vulnerability Management Center, this integration has reduced the time required to deliver vulnerability information to affected companies from one month to one week.
KISA’s updated framework covers the entire lifecycle of vulnerability management, including discovery, verification, remediation, and information sharing. The agency is specifically targeting external public web pages of critical infrastructure and major commercial or open-source software.
The agency is piloting a public-private partnership initiative that encourages companies to allow external security researchers to assess their systems. This initiative relies on VDPs to define the scope of testing and CVDs to ensure companies have sufficient time to patch vulnerabilities before public disclosure.
Legislative research is expected to conclude by the end of 2026, with the goal of providing a safe harbor for security researchers who currently face potential legal repercussions for unauthorized access during testing.
Чому це важливо
As AI-powered tools accelerate the pace of cyberattacks, KISA is shifting toward a proactive risk management model that prioritizes high-risk vulnerabilities over volume-based responses. The agency reports that the Forum of Incident Response and Security Teams (FIRST) has revised its 2026 vulnerability disclosure forecast upward by 46.3% to 66,000, citing the proliferation of autonomous AI discovery tools. By formalizing Vulnerability Disclosure Policies (VDP) and Coordinated Vulnerability Disclosure (CVD) frameworks, KISA aims to bridge the gap between security researchers and private enterprises, while seeking legislative changes to protect researchers from legal risks associated with authorized security testing.
The surge in AI-driven vulnerability discovery tools has created a 'wave' of security disclosures, necessitating a shift from reactive patching to risk-based prioritization. KISA’s focus is on identifying internet-exposed assets and the likelihood of exploitation before an incident occurs.
The reduction in notification time from one month to one week represents a significant improvement in the speed of the national security response, potentially limiting the window of opportunity for attackers to exploit known vulnerabilities.
The proposed 'Korean Glasswing' approach highlights a strategic move toward sovereign AI security, emphasizing the need for models that understand the specific threat landscape and linguistic nuances of the Korean domestic environment.
Інтерактивний механізм: як він насправді працює
Дослідіть технологію, що лежить в основі цієї розробки, в інтерактивному режимі.
crm_get_transaction(id='4092').Which of these is a common misconception about AI Ethics?
Що дивитися далі
KISA is currently pursuing legislative research to establish a legal foundation for public-private security collaboration, aiming to resolve current legal ambiguities regarding unauthorized access during security assessments. Additionally, the agency is advocating for the development of security-specialized foundation models trained on domestic Korean security data. Officials have proposed a 'Korean Glasswing' initiative—a collaborative framework modeled after existing international efforts—to systematically evaluate the performance and safety of these models across various industrial sectors.
Watch for the outcome of the legislative research, which will determine how South Korea balances the need for robust security testing with the legal protections required for ethical hackers.
Monitor the development of the 'Korean Glasswing' initiative, specifically whether it results in a centralized government-led platform for testing and validating security-specialized AI models.
Observe whether the integration of OpenAI’s GTAC program expands to cover a broader range of private sector assets or if KISA shifts toward domestic alternatives as part of its security-specialized model strategy.