返回新聞
安全性AI Understanding 簡報

ChosunBiz 通報 Microsoft 安全主管表示人工智慧可以將網路防禦轉向防禦者

Microsoft 安全主管 Kim Tae-su 告訴 ChosunBiz,人工智慧可以幫助防禦者大規模檢查漏洞,同時描述了 Microsoft 的 MDASH 系統並敦促韓國加強其網路安全產業。

5 min readRead the original reporting
Source-provided image accompanying ChosunBiz reports Microsoft security executive says AI could shift cyber defense toward defenders
歸因報告來源記錄
出版商
biz.chosun.com
來源連結
biz.chosun.comhttps://biz.chosun.com/en/en-it/2026/08/30/QKQO6EEOCZHY5O5SGHW25OVMD4/?outputType=amp
來源類型
新聞媒體的報道-不是第一方文件。

我們無法獨立確認的內容: 此聲明歸因於指定的商店。我們沒有根據第一方文件對其進行驗證。 (biz.chosun.com)

背景60 秒內了解這一點

從這裡開始

關鍵術語

管道
預處理、模型步驟和後處理階段的有序工作流程。
偏見
數據或模型行為中一致的錯誤或不公平模式。
測試一下自己AI 代理測驗

發生了什麼事

ChosunBiz reported that Kim Tae-su, Microsoft’s corporate vice president for security, believes AI could eventually reverse the traditional advantage held by cyber attackers. Kim also described MDASH, an AI-based vulnerability detection system that the article says is mandatory in Microsoft Windows’ development and uses more than 100 specialized sub-agents.

ChosunBiz reported that Kim Tae-su made the comments in an interview on Aug. 26, after delivering a keynote at SMARTCLOUD SHOW 2026 in Seoul. Kim argued that attackers historically needed to find only one exploitable weakness, while defenders had to account for many possibilities. According to ChosunBiz, he said advances in AI could make it realistically possible for defenders to examine those possibilities before attacks occur. He also acknowledged that attackers are currently adopting AI quickly, while defenders face regulation, compliance and cost constraints.

The article says Kim described MDASH as a system that combines multiple AI agents by work stage and role. It reportedly first builds a threat model from software architecture and historical vulnerability information. More than 100 sub-agents then search for weaknesses. Agents assigned hacker, developer and defender roles cross-check the findings, generate proof-of-concept code to test whether an attack is feasible, and produce patches intended to fix the underlying issue. ChosunBiz reported that MDASH uses different AI models for some roles to reduce the chance that the same model will reproduce the same .

According to the report, unresolved disagreements are handled through a vote by three models, with a vulnerability reported only when at least two models classify it as a real bug. ChosunBiz said the system is currently used in the Microsoft Windows organization’s continuous integration and continuous delivery and is mandatory in the development process. The article reported that, within four months of adoption, MDASH found vulnerabilities equivalent to 66% of all vulnerabilities discovered in Windows during the previous year.

That performance claim is not independently confirmed in the supplied source. ChosunBiz did not provide a public technical paper, audit, vulnerability list, test protocol, false-positive rate, or independent assessment of the 66% comparison. The article also said MDASH was commercialized quickly and that many companies in South Korea and abroad were adopting it, but it did not name those companies or provide adoption figures. Kim’s background, including his leadership of Team Atlanta in the 2025 DARPA AI Cyber Challenge, was also reported by ChosunBiz; the supplied source does not independently document those credentials.

來源詳情: biz.chosun.com ↗

為什麼這很重要

The report presents a concrete example of AI being used in software security workflows, including vulnerability discovery, cross-checking, proof-of-concept generation and patch development. If the reported deployment and results are independently substantiated, the system could affect how large software organizations allocate security testing and engineering resources.

The report matters because it describes AI as an active component of defensive software security rather than as a general productivity tool. MDASH is presented as operating across several stages of the vulnerability process: modeling threats, searching code, testing exploitability and proposing patches. That workflow could be consequential if it consistently identifies complex flaws that conventional testing misses and if human security engineers can safely review its outputs.

Kim’s central argument is broader than the product description. ChosunBiz reported that he expects AI to narrow the asymmetry between attackers and defenders because defenders control the code-release process and can examine systems before deployment. That is a forecast and an executive’s assessment, not evidence that the balance has already shifted across the cybersecurity sector. The article itself says Kim believes attackers currently retain an advantage because defensive organizations face additional legal, compliance and spending constraints.

The report also connects AI security tools to South Korea’s industrial policy. Kim told ChosunBiz that Korea has highly capable security workers but lacks an industrial base that sufficiently supports them. He cited lower pay for security personnel than for general software developers and said Korean specialists often seek opportunities abroad. Those comments identify workforce retention and compensation as practical constraints, although the article does not provide labor-market data to measure the claimed wage gap or migration.

Kim further warned that AI could replace some junior security work while increasing demand for people who understand AI, software development and security together. That possibility has public significance because entry-level security tasks can provide training and a pathway into the profession. Whether AI removes those opportunities, changes them, or creates new ones cannot be determined from this interview. The report offers no workforce study, employment figures or evidence that MDASH has already changed staffing at Microsoft or elsewhere.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

接下來看什麼

The key questions are whether Microsoft publishes evidence supporting MDASH’s reported performance, how the system performs outside Windows, and whether it reduces missed vulnerabilities without creating excessive false positives or new risks. The broader workforce effects described by Kim also remain uncertain.

The first priority is independent verification of MDASH’s reported results. Useful evidence would include Microsoft technical documentation, a peer-reviewed or independently reviewed evaluation, representative vulnerability records, and clear definitions of what “equivalent to 66%” means. Observers would also need to know how many findings were confirmed, how many were duplicates or false positives, how patches were tested, and whether the system found flaws that human teams or existing automated tools had missed.

The system’s use of proof-of-concept code deserves particular scrutiny. ChosunBiz reported that MDASH generates such code to verify attack feasibility, but the source does not explain what safeguards isolate those tests, prevent accidental exploitation, or control access to generated material. Future reporting should examine whether the workflow operates only in authorized environments and how Microsoft handles proof-of-concept artifacts that could be repurposed.

The scale and durability of deployment are also unknown. ChosunBiz said MDASH is mandatory in the Windows development process and that many other corporations are adopting it, but gave no dates for broader rollout, customer names, pricing, deployment requirements or evidence from outside Microsoft. Confirmation of use across independent organizations would help distinguish a company-specific engineering program from a more general change in commercial cybersecurity practice.

Finally, the workforce and strategic claims need evidence beyond Kim’s assessment. South Korea’s government, universities and security companies could clarify whether compensation, training and retention are changing, and whether AI is expanding or narrowing entry-level roles. More broadly, future evaluations should test whether AI-assisted defense improves real-world resilience without giving attackers comparable advantages. The supplied source establishes that a senior Microsoft security executive made these claims and described a deployed system; it does not establish that AI has already given defenders the upper hand.

相關指引和測驗

人工智慧代理人工智慧模型解釋AI 倫理人工智慧培訓測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?