AI disguised malware also increased fivefold... Emphasis on continuous monitoring
Quick Look
- According to a Kaspersky report, in the second quarter of this year, AI and LLM service vulnerabilities increased 10 times compared to the same period last year to 935 cases, and serious vulnerabilities increased 5 times to 119 cases.
- In addition, more than 33,300 cases of attacks on small and medium-sized businesses using malicious software disguised as AI services were detected, an increase of approximately five times compared to the same period last year, emphasizing the need for continuous security monitoring.
AI-generated summary
Why It Matters
Recently, vulnerabilities in artificial intelligence services have been rapidly increasing, and according to Kaspersky's quarterly report, vulnerabilities in AI and LLM services have increased tenfold compared to the same period last year.
AI disguised malware also increased fivefold... Emphasis on continuous monitoring
(Seoul = Yonhap News) Reporter Hayoung Kwon = Recently, vulnerabilities found in artificial intelligence (AI) services have been found to be rapidly increasing.
According to the 'Quarterly Exploit and Vulnerability Report' released by global cybersecurity company Kaspersky on the 7th, the number of vulnerabilities recorded in AI and Large-Scale Language Model (LLM) services in the second quarter of this year was 935, a tenfold increase from the fourth quarter of last year.
Among these, there were 119 serious vulnerabilities, which is about five times more than the number at the end of last year.
When analyzing AI-related software (SW) vulnerabilities by type, weak access control to important system objects, authentication/authorization implementation errors, and injection (malicious command injection) vulnerabilities were most frequently discovered.
“AI tools and plugins are effective in automating tasks, but the rapid adoption of AI across organizations is creating new security challenges,” said Kaspersky malware expert Alexander Kolesnikov. “To maintain security, we need to secure real-time visibility into infrastructure and access control.”
In addition to vulnerabilities in the AI service itself, attacks using malicious software disguised as AI services have also shown an increase.
According to Kaspersky's Small and Medium Business (SMB) Threat Report, in the first four months of this year, more than 33,300 cases of attacks on small and medium-sized businesses using malicious and unwanted PC software disguised as popular AI services were detected, an increase of approximately five times compared to the same period last year.
Lee Hyo-eun, head of Kaspersky's Korea branch, said, "AI adoption is accelerating across Korean industries, and companies are facing new security risks. Rather than relying solely on applying existing patches, companies should protect their AI environments with a comprehensive security approach that combines continuous risk monitoring and preemptive protection."
Open Questions
- Specifically, which AI service had the most vulnerabilities discovered?
- What AI services are most imitated in malware spoofing cases?
- What is the specific level of security measures companies are currently taking?







