发生了什么
Chosunbiz reported that Cloudflare executives speaking at a media education session in Seoul warned that AI agents are generating rapidly increasing network traffic and expanding the number of services that companies must secure. The executives urged organizations to identify internal AI tools, limit access by identity and permission, control unapproved MCP connections and protect sensitive information sent in prompts. Cloudflare also discussed AI-assisted cyberattacks and its planned expansion of post-quantum authentication support.
Chosunbiz reported that Goran Risticsevich, Cloudflare’s executive vice president and managing director for Asia-Pacific, said AI-agent traffic on Cloudflare’s network had increased by more than 1,700% from a year earlier and represented about 60% of all network traffic. The article did not provide the underlying baseline, the precise measurement period, the geographic scope of the figures, the definition of AI-agent traffic or an independent source for the estimates. Those omissions make the scale of the increase difficult to evaluate, even though the claims were presented as the central evidence for Cloudflare’s warning.
Chosunbiz reported that Risticsevich contrasted ordinary human browsing with agents that can connect to many websites and servers at once. The article said this creates a larger security-management problem because companies need to know which AI system is accessing which data and systems, and whether that access is necessary. The report also described shadow AI, in which employees use unapproved AI services and may send sensitive internal information to external models. It identified shadow MCP as a related risk involving unapproved Model Context Protocol connections to external tools or internal systems.
Cloudflare 告诉 Chosunbiz,公司应该首先识别内部使用的人工智能工具,然后控制其数据和网络访问。该公司建议阻止包含敏感信息的提示,并对 MCP 服务器访问应用零信任原则,以便用户只能访问其身份和权限允许的应用程序。这些建议是作为 Cloudflare 的指导意见提出的,而不是独立报告的监管标准、客户研究或受控评估的结果。该文章没有指出遭受影子 AI 或影子 MCP 事件的具体组织。
该报告还介绍了 Cloudflare 参与与 Anthropic 共同开展的安全联盟 Project Glasswing 的情况。 Chosunbiz 报道称,Cloudflare 提前获得了 Anthropic 的 Mythos AI 模型的访问权限,供其内部安全团队进行测试,Cloudflare 表示,测试表明 AI 已经变得更有能力链接多个漏洞,并且更快地发现新漏洞。该文章没有提供测试设计、对照组、测量结果或独立验证。 Cloudflare 高管认为,组织不能仅仅依赖于一次修补一个漏洞,而应该加强更广泛的安全控制。
为什么这很重要
AI agents can interact with many external websites, tools and internal systems on a user’s behalf, creating security and data-governance risks that differ from those of ordinary software users. The report offers practical concerns around shadow AI, shadow MCP and vulnerability chaining, but its most significant statistics and test results are Cloudflare claims reported by Chosunbiz and were not independently confirmed.
该报告的实际意义在于,人工智能代理可以扩大公司员工、模型、工具和数据存储之间交互的数量和速度。传统的应用程序可能具有一组定义的权限和目的地,而代理可以在其接收的权限内动态选择工具或服务。如果这些权限过于广泛,受损的代理、恶意指令或管理不善的集成可能会暴露信息或触发超出用户预期的操作。 Chosunbiz 的说法支持加强治理的必要性,但没有确定这些故障发生的频率。
影子人工智能是一个常见的企业问题,但报告表明,MCP 可以通过将模型连接到可以检索信息或执行操作的系统来使其更具操作意义。即使模型本身不是问题根源,未经批准的连接也可能会产生风险。因此,本文对基于身份的访问和最小权限的强调与采用代理工具的公司相关。然而,Chosunbiz 没有报告独立证据表明影子 MCP 已经在韩国普遍存在,也没有量化其造成的损失。
网络安全主张也很重要,因为人工智能可能会影响防御周期的双方。据 Chosunbiz 报道,Cloudflare 的账户将人工智能系统描述为能够更好地将漏洞链接到攻击路径,并更快地发现漏洞。如果得到独立证实,这将增加防御者自动化资产库存、检测、优先级和响应的压力。然而消息来源没有提供有关 Mythos 测试的技术细节,也没有证据表明报告的结果可以转化为针对真实组织的成功攻击。因此,该声明应被视为安全公司的警告,而不是对当前犯罪能力的验证措施。
后量子问题增加了对长期基础设施的担忧。 Chosunbiz 报道称,Cloudflare 支持抗量子加密,并预计到 2028 年提供全面的抗量子身份验证,而一位高管表示,业界预计可能在 2030 年左右出现 Q Day。从易受攻击的加密系统迁移可能需要数年时间,因为必须对证书、协议、设备和第三方服务进行盘点和升级。该报告没有确定这些日期是共识预测,也没有解释 Cloudflare 当前支持的范围。公共价值在于强调移民规划,而不是将日期视为预测。
互动机制:它实际上是如何运作的
以交互方式探索这一发展背后的基础技术。
crm_get_transaction(id='4092').An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?
接下来看什么
The main questions are whether Cloudflare’s traffic estimates can be independently documented, how much of the reported activity represents useful agent work rather than automated requests, and whether the company’s security recommendations produce measurable reductions in unauthorized access or data leakage. Cloudflare’s stated plan to fully support quantum-resistant authentication by 2028 is also a future commitment rather than a completed deployment.
首先,Cloudflare的流量声明需要独立测量。有用的后续报告将确定 Cloudflare 算作人工智能代理的内容、与同期相比是否有 1,700% 的增长、60% 的数字是否适用于全球或特定细分市场,以及爬虫、搜索、推理和自主代理流量如何分离。如果没有这些信息,统计数据只能显示 Cloudflare 的评估,但无法可靠地描述整个互联网或韩国网络。
其次,采用代理系统的公司应披露他们如何库存模型和工具使用、批准 MCP 服务器、限制权限并防止敏感提示数据离开受控环境。该报告没有提供任何证据表明 Cloudflare 提出的控制措施已经过独立测试。后续证据应包括真实的部署结果、记录的事件、审计结果或比较评估,以显示零信任控制是否减少未经授权的工具调用、数据泄露或有害行为。
第三,Glasswing 项目的主张值得进行技术审查。 Chosunbiz 的报告没有说明哪些漏洞被链接、模型是如何提示的、测试是否使用真实环境、与现有工具相比性能如何,或者 Anthropic 是否独立同意 Cloudflare 的解释。独立研究人员和维护者应该寻找可重复的方法和公开描述的结果,然后再对人工智能支持的漏洞发现速度得出结论。
最后,Cloudflare 的后量子时间表应作为产品和迁移承诺进行跟踪。后续报告可以阐明哪些加密功能已经可用、全面的抗量子身份验证将涵盖哪些内容,以及客户是否必须更改证书、软件或硬件。该消息人士还没有解决所报告的人工智能代理流量激增是集中在少数大型服务中还是反映了广泛采用。这些未知因素对于判断 Cloudflare 警告的紧迫性和公众影响至关重要。