As the use of artificial intelligence (AI) for detecting security vulnerabilities becomes more advanced, the focus of security management is shifting from 'discovery' to 'verification and action.' With the rapid increase in publicly disclosed vulnerabilities, the ability to identify high-risk targets and prioritize swift action is becoming crucial.
According to the Korea Internet & Security Agency (KISA), the number of disclosed vulnerabilities (CVE) worldwide reached 48,185 last year, a 20.6% increase from the previous year. This averages to about 132 cases per day, and it is projected to rise to approximately 66,000 this year. KISA attributes this increase primarily to the proliferation of AI-based autonomous vulnerability detection tools.
Baek Seung-kwon, head of KISA's Vulnerability Management Center, stated on September 21, "It is no longer just about how many vulnerabilities are discovered; it is increasingly important to accurately identify which of the discovered vulnerabilities are genuinely dangerous and to act on them swiftly. We are moving from the traditional virtues of vulnerability management, which focused on discovery, to verification and action."
Not all publicly disclosed vulnerabilities lead to actual attacks. Therefore, the process of discerning real exploitation potential and prioritizing responses is becoming increasingly important. KISA reports that the bottleneck in vulnerability management is shifting from discovery to verification and patching.
The speed gap between attacks and defenses is also widening. KISA noted that 29% of vulnerabilities were exploited on the day of disclosure or before, while the average time for companies to patch vulnerabilities increased from 32 days last year to 43 days this year. Vulnerabilities accounted for 31% of the initial infiltration routes in security incidents. While attacks are accelerating on an hourly basis, responses remain limited to monthly timelines.
Baek emphasized that relying solely on post-incident responses has its limitations. He stated, "It is crucial to identify exposed assets and vulnerabilities on the internet before incidents occur and to select those with a high likelihood of exploitation. We need to shift vulnerability management from reactive responses to proactive threat management."
In cybersecurity, AI serves as both a tool for attackers and defenders. Baek explained, "Using AI allows for faster analysis of large volumes of code compared to human analysis, helping to identify potential vulnerabilities and verify whether they could lead to actual attacks. We should not view AI solely as a facilitator of hacking; we must also leverage it to enhance our defensive speed."
KISA manages the entire cycle of vulnerability management—from discovery to verification, action support, and dissemination—through its Vulnerability Management Center. It provides information on domestic and international vulnerabilities and patches via the Vulnerability Information Portal (KNVD) and operates a reward system for reporting vulnerabilities, along with a collaborative disclosure system with businesses and organizations.
AI is also being tested for defensive purposes. Since May, KISA and the Ministry of Science and ICT have participated in OpenAI's GTAC program, utilizing GPT-5.5 Cyber to check vulnerabilities in publicly accessible web pages and commercial and open-source software. Vulnerabilities identified by AI are verified for validity and potential exploitation before being addressed by the respective companies.
Baek noted that while AI can accelerate the discovery and analysis of vulnerabilities, the role of humans remains critical in verifying actual risks and determining action priorities. With AI quickly analyzing large numbers of vulnerability candidates, humans can focus on discerning real exploitation potential and making decisions on responses.
Baek concluded, "The virtues of vulnerability management are shifting from discovery to verification and action, and speed is synonymous with defense."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.

