Security

Threats Targeting Enterprise AI Services Rise, Making Visibility Essential for Security Control

TECHWORLD ·

The number of publicly disclosed vulnerabilities in large language models, AI tools, and plugins offering similar functionality in 2025–2026 (based on Kaspersky vulnerability management data). [Photo: Kaspersky Quarterly Exploit and Vulnerability Report]

✦ AI Summary

According to Kaspersky's "Quarterly Exploits and Vulnerabilities Report," released on August 27, vulnerabilities found in AI services surged as AI adoption expanded.

Based on Kaspersky Vulnerability Management data, vulnerabilities in AI and LLM services in the second quarter of 2026 totaled 935, up 10-fold from the fourth quarter of 2025, while critical vulnerabilities rose to 119, about 5 times higher than at the end of 2025.

Kaspersky identified weaknesses in core system object access controls, improper authentication and authorization implementation, and injection vulnerabilities as the main issues, and said a security approach that includes real-time visibility is needed.

As AI has emerged and spread across a wide range of industries has accelerated, vulnerabilities in AI services are also rising rapidly. As a result, the need for a security environment to ensure safe use of AI is growing.

Kaspersky released its "Quarterly Exploits and Vulnerabilities Report" on August 27. The report shows that vulnerabilities found in AI services are surging as AI adoption expands.

According to Kaspersky Vulnerability Management data, vulnerabilities in AI and LLM services totaled 935 in the second quarter of 2026, a 10-fold increase from the fourth quarter of 2025. In the same period, 119 critical vulnerabilities were recorded in the second quarter of 2026, about 5 times the number recorded at the end of 2025.

Kaspersky pointed to weaknesses in access control mechanisms for core system objects, improper authentication and authorization implementation, and injection vulnerabilities as the main problems in AI-related software. Kaspersky also noted that there are additional issues beyond these service vulnerabilities themselves.

AI tools, plugins, and related technologies are supporting work automation, and AI adoption within organizations is expanding rapidly. However, the wider use of AI is creating new security challenges, and the use of AI services is also continuing to rise.

Recently, attacks using malware disguised as AI services have been increasing, and attempts at related attacks are expected to continue rising as AI service use grows. Security industry experts said existing patch management alone is insufficient to maintain security at the current level, and Alexander Kolesnikov, a Kaspersky malware expert, advised that maintaining security requires real-time visibility beyond traditional patch management.

Lee Hyo-eun, president of Kaspersky Korea, said that as AI adoption accelerates across Korean industry, businesses are seeing gains in operational efficiency from AI use, but are also facing new security risks along with AI deployment. She added that many domestic companies overlook building security controls during AI adoption, and that access control gaps and weaknesses in authentication systems make it easy for threat actors to exploit them. She emphasized that a comprehensive security approach is needed to protect AI environments, along with a combination of continuous risk monitoring and proactive protection.

Source: TECHWORLD · Kim Hye-jin
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406603

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.