
정부가 민간 주요정보통신기반시설 16개사, 상용SW 5개사, 오픈소스 144종을 점검한 결과 취약점 523건이 확인됐으나 AI 활용 점검에는 별도 예산이 없어 오픈AI의 GTAC 프로그램을 통한 무상 지원에 의존하고 있는 것으로 나타났다.
AI-generated summary
정부는 올해 6월부터 9월까지 민간 주요정보통신기반시설, 상용SW, 오픈소스를 대상으로 취약점 점검을 실시했으며, 최근 금융권 해킹 사고에서 AI 기반 공격 도구가 사용된 정황이 포착되면서 사이버 보안 우려가 커지고 있다.
기반시설 304건·상용SW 135건·오픈소스 84건 확인
AI 활용 점검 별도예산 없어 해외 빅테크 지원에 의존
(서울=연합뉴스) 권하영 기자 = 정부가 올해 6월부터 9월 말까지 민간 주요정보통신기반시설과 상용 소프트웨어(SW), 오픈소스를 대상으로 점검한 결과 취약점이 총 523건 확인된 것으로 나타났다.
최근 금융권 해킹 사고에서 인공지능(AI) 해킹 도구가 활용된 정황이 포착되는 등 AI 기반 사이버 위협이 커지는 가운데 나온 결과다.
◇ 민간 기반시설·SW·오픈소스서 취약점 523건…금융권 넘어 확산 우려
6일 국회 과학기술정보방송통신위원회 소속 이주희 더불어민주당 의원실이 과학기술정보통신부로부터 제출받은 자료에 따르면, 민간 주요정보통신기반시설 16개사(대기업 6곳, 중견기업 3곳, 중소기업 2곳, 비영리단체 5곳)를 점검한 결과 취약점 304개가 발견됐다.
상용SW는 5개사(중견기업 1곳, 중소기업 4곳)에서 135개, 오픈소스는 144종에서 84개의 취약점이 각각 확인됐다. 오픈소스의 경우 개인 또는 공동 개발하는 경우가 많아 점검 대상(개발 주체)을 특정하지 않았다.
이번 점검 결과는 최근 금융권을 강타한 해킹 사고와 맞물려 주목된다.
최근 금융당국에 따르면 신한·KB국민·하나·BNK부산은행과 예가람·웰컴저축은행, 현대캐피탈 등 7개사의 침해 사고에서 동일한 공격자의 인터넷주소(IP)가 여러 곳에서 발견됐다.
공격자는 IP를 바꿔가며 다수 금융사를 대상으로 대량의 자동화된 공격을 한 것으로 파악됐다.
은행을 공격한 IP에서는 중국어를 중심으로 깃허브(GitHub)에 오픈소스로 공개된 대규모언어모델(LLM) 기반 자율형 침투테스트 시스템인 'ARTEX AI'의 흔적이 확인돼 경찰청이 조사 중이다.
민간 기업은 그러나 폐쇄망 기반 보안 체계를 갖춘 금융권보다 오히려 보안이 취약한 경우가 많아, 금융권을 넘어 산업·기업 전반으로 AI 보안 우려가 확산하는 양상이다.
◇ AI 취약점 점검 예산 '0원'…해외 빅테크 무상 프로그램 의존
하지만 정작 AI를 활용한 민간 취약점 점검 사업에는 별도 예산이 편성되지 않은 것으로 나타났다.
앞서 과기정통부는 지난 5월 과학기술관계장관회의에 보고한 '민간 정보보호 추진계획(안)'에서 AI 취약점 공개에 대응하기 위한 민관합동 대응체계를 마련하고, 한국인터넷진흥원(KISA) 내 취약점관리센터를 중심으로 취약점·패치 관리를 일원화하고 긴급대응체계를 갖추겠다고 밝힌 바 있다.
당시 계획안은 해당 센터를 1개 단 40명 규모로 구성하되 "기존 인력을 우선 활용"하는 방식으로 꾸리겠다고 명시했다.
그러나 실제로는 프론티어 AI를 활용한 취약점 점검이 별도 예산 없이 추진되고 있으며, 과기정통부는 내년도 예산을 요청했으나 정부안에 반영되지 않은 상황이라고 밝혔다.
이 같은 취약점 점검은 오픈AI의 'GTAC' 프로그램에 참여해 고성능 보안 AI 모델인 'GPT-5.5 Cyber'를 무상으로 지원받고 있어 가능한 형편이다.
정부가 내세운 취약점·패치 관리 일원화 체계가 자체 예산 없이 해외 빅테크의 무상 프로그램에 의존해 운영되고 있는 셈으로, 전문가들은 AI를 활용한 공격이 갈수록 대량화·자동화하는 만큼 민관 대응체계의 안정적 운영을 위한 예산 확보가 필요하다고 지적한다.
AI outlook — possibilities, not facts
내년도 예산안에 AI 취약점 점검 관련 사업이 재반영될 가능성이 있다.
Possible · Within months
![[AI Prism] Domestic AI companies “toward an open ecosystem”... Lisa Su “Let’s go together” (Comprehensive 2nd edition)](/api/img?u=https%3A%2F%2Fimg.yna.co.kr%2Fphoto%2Fyna%2FYH%2F2026%2F10%2F07%2FPYH2026100704790001300_P2.jpg&w=320&q=72&f=webp)
AMD Chairman Lisa Su announced that she will cooperate with 13 domestic AI semiconductor companies to build a heterogeneous AI infrastructure that combines CPU/GPU and domestic AI semiconductors, develop it into a global reference model, and support the establishment of an AI research base in Korea and participation in the ROCm ecosystem.

Bloomberg reported that Chinese AI company DeepSeek is expected to secure close to 100 billion yuan (about 20 trillion won) in funding in its ongoing investment round. CATL and Tencent participated as major investors, and Deepseek's corporate value is expected to reach at least 500 billion yuan (about 100 trillion won).
![[AI Pick] Lisa Su “Betting on Korea’s AI ecosystem”… Recruiting hundreds of researchers](/api/img?u=https%3A%2F%2Fimg.yna.co.kr%2Fetc%2Finner%2FKR%2F2026%2F10%2F07%2FAKR20261007049900017_01_i_P2.jpg&w=320&q=72&f=webp)
AMD CEO Lisa Su visited Korea and announced plans to establish an AI research base (CoE) in Korea, promising to hire hundreds of researchers and expand infrastructure and industry-academic cooperation with domestic companies and universities. Cooperation discussions with 14 companies, including Rebellion, Furiosa AI, and Mango Boost, are also scheduled.

Finland's Licensing Supervisory Authority ordered Google to stop work on data center site development in the Muhos and Kayani regions until an environmental impact assessment is completed. Google planned to invest at least 13 billion euros in Finland over the next two years, but there are concerns that this measure will delay the project.

Antropic has expanded 'Project Glasswing', which supports the use of the AI model 'Claude Mythos' for cybersecurity, and introduced a three-level access authority system of defense access, red team access, and special access. Existing participating organizations will automatically be converted to special access, and new organizations will be verified and qualified in cooperation with the U.S. government. Antropic said that it discovered more than 129,000 software vulnerabilities through the program between April and July, of which 33,000 were classified as critical or high risk. However, JP Morgan Chase CEO Jamie Dimon voiced concerns, warning that Antropic's Mythos model has increased global cybersecurity risks tenfold.

Apple is collaborating with LG Electronics to jointly develop smart home devices, which will be manufactured and sold under the LG brand, while Apple will participate in design and function development. The product will be linked to Apple's new smart home hub, which is interpreted as a strategy to challenge Amazon's Ring and Google's Nest.