
As a result of the government's inspection of 16 major private information and communication infrastructure companies, 5 commercial SW companies, and 144 types of open source, 523 vulnerabilities were identified, but there was no separate budget for AI utilization inspection, so it was found that it was relying on free support through OpenAI's GTAC program.
AI-generated summary
The government conducted vulnerability checks on major private information and communication infrastructure, commercial software, and open source from June to September of this year, and concerns about cyber security are growing as circumstances in which AI-based attack tools were used in recent financial sector hacking incidents were discovered.
304 infrastructure, 135 commercial SW, 84 open source confirmed
There is no separate budget for AI utilization inspection, so we rely on support from overseas big tech.
(Seoul = Yonhap News) Reporter Hayoung Kwon = As a result of the government's inspection of major private information and communication infrastructure, commercial software (SW), and open source from June to the end of September this year, a total of 523 vulnerabilities were found.
This is a result that comes as AI-based cyber threats are growing, such as the use of artificial intelligence (AI) hacking tools in recent financial sector hacking incidents.
◇ 523 vulnerabilities in private infrastructure, software, and open source… Concerns about spreading beyond the financial sector
According to data submitted from the Ministry of Science and ICT by the office of Democratic Party lawmaker Lee Joo-hee, a member of the National Assembly Science, Technology, Information, Broadcasting and Communications Committee on the 6th, 304 vulnerabilities were discovered as a result of an inspection of 16 major private information and communication infrastructure companies (6 large companies, 3 mid-sized companies, 2 small and medium-sized companies, and 5 non-profit organizations).
135 vulnerabilities were identified in 5 companies (1 mid-sized company, 4 small and medium-sized companies) in commercial SW, and 84 vulnerabilities in 144 types of open source. In the case of open source, it is often developed individually or jointly, so the inspection target (development subject) was not specified.
The results of this inspection are attracting attention in conjunction with the recent hacking incident that hit the financial sector.
According to the financial authorities, the Internet address (IP) of the same attacker was discovered in several places in the breaches of seven companies, including Shinhan, KB Kookmin, Hana, BNK Busan Bank, Yegaram, Welcome Savings Bank, and Hyundai Capital.
It was discovered that the attacker carried out a large number of automated attacks targeting multiple financial companies by changing IP addresses.
The National Police Agency is investigating traces of 'ARTEX AI', a large-scale language model (LLM)-based autonomous penetration testing system released as open source on GitHub, focusing on Chinese, in the IP that attacked the bank.
However, private companies often have weaker security than the financial sector, which has a closed network-based security system, and concerns about AI security are spreading beyond the financial sector to industries and companies.
◇ AI vulnerability inspection budget ‘0 won’… Reliance on free programs from overseas big tech
However, it turned out that no separate budget was allocated for private vulnerability inspection projects using AI.
Previously, the Ministry of Science and ICT announced in the 'Private Information Protection Promotion Plan (draft)' reported to the Science and Technology Ministerial Meeting in May that it would establish a joint public-private response system to respond to disclosure of AI vulnerabilities, unify vulnerability and patch management centered on the Vulnerability Management Center within the Korea Internet & Security Agency (KISA), and establish an emergency response system.
At the time, the plan stated that the center would be organized with only 40 people, but would be organized in a way that "preferentially utilizes existing manpower."
However, in reality, vulnerability inspection using Frontier AI is being carried out without a separate budget, and the Ministry of Science and ICT has requested a budget for next year, but has not reflected it in the government plan.
Such vulnerability inspection is possible because the company participates in OpenAI's 'GTAC' program and receives free support for 'GPT-5.5 Cyber', a high-performance security AI model.
The government's unified vulnerability and patch management system is being operated without its own budget and relying on free programs from overseas big tech. Experts point out that as attacks using AI are becoming increasingly mass-scaled and automated, it is necessary to secure a budget for the stable operation of the public-private response system.
AI outlook — possibilities, not facts
There is a possibility that projects related to AI vulnerability inspection will be re-reflected in next year's budget.
Possible · Within months
![[AI Prism] Domestic AI companies “toward an open ecosystem”... Lisa Su “Let’s go together” (Comprehensive 2nd edition)](/api/img?u=https%3A%2F%2Fimg.yna.co.kr%2Fphoto%2Fyna%2FYH%2F2026%2F10%2F07%2FPYH2026100704790001300_P2.jpg&w=320&q=72&f=webp)
AMD Chairman Lisa Su announced that she will cooperate with 13 domestic AI semiconductor companies to build a heterogeneous AI infrastructure that combines CPU/GPU and domestic AI semiconductors, develop it into a global reference model, and support the establishment of an AI research base in Korea and participation in the ROCm ecosystem.

Bloomberg reported that Chinese AI company DeepSeek is expected to secure close to 100 billion yuan (about 20 trillion won) in funding in its ongoing investment round. CATL and Tencent participated as major investors, and Deepseek's corporate value is expected to reach at least 500 billion yuan (about 100 trillion won).
![[AI Pick] Lisa Su “Betting on Korea’s AI ecosystem”… Recruiting hundreds of researchers](/api/img?u=https%3A%2F%2Fimg.yna.co.kr%2Fetc%2Finner%2FKR%2F2026%2F10%2F07%2FAKR20261007049900017_01_i_P2.jpg&w=320&q=72&f=webp)
AMD CEO Lisa Su visited Korea and announced plans to establish an AI research base (CoE) in Korea, promising to hire hundreds of researchers and expand infrastructure and industry-academic cooperation with domestic companies and universities. Cooperation discussions with 14 companies, including Rebellion, Furiosa AI, and Mango Boost, are also scheduled.

Finland's Licensing Supervisory Authority ordered Google to stop work on data center site development in the Muhos and Kayani regions until an environmental impact assessment is completed. Google planned to invest at least 13 billion euros in Finland over the next two years, but there are concerns that this measure will delay the project.

Antropic has expanded 'Project Glasswing', which supports the use of the AI model 'Claude Mythos' for cybersecurity, and introduced a three-level access authority system of defense access, red team access, and special access. Existing participating organizations will automatically be converted to special access, and new organizations will be verified and qualified in cooperation with the U.S. government. Antropic said that it discovered more than 129,000 software vulnerabilities through the program between April and July, of which 33,000 were classified as critical or high risk. However, JP Morgan Chase CEO Jamie Dimon voiced concerns, warning that Antropic's Mythos model has increased global cybersecurity risks tenfold.

Apple is collaborating with LG Electronics to jointly develop smart home devices, which will be manufactured and sold under the LG brand, while Apple will participate in design and function development. The product will be linked to Apple's new smart home hub, which is interpreted as a strategy to challenge Amazon's Ring and Google's Nest.