Security

As Vulnerabilities Pile Up, KISA Speeds Verification and Remediation with AI

IT DAILY ·

AI-generated image

✦ AI Summary

As AI-powered software vulnerability detection spreads, publicly disclosed vulnerabilities are also rising rapidly, and verification and remediation after detection have emerged as a challenge.

KISA is using the Vulnerability Management Center and AI to speed up verification and is reorganizing its response framework around high-risk vulnerabilities.

FIRST said CVE disclosures this year could reach about 66,000, and VulnCheck analysis showed that 29% of 884 vulnerabilities actually exploited were exploited on or before the day they were disclosed.

As AI-powered software vulnerability detection spreads, the number of publicly disclosed vulnerabilities is also rising rapidly. According to the security industry on the 22nd, verification and remediation after detection have emerged as new challenges.

In this environment, the direction of response is also changing. Prioritizing based on exploitability, rather than applying a blanket standard, is becoming the preferred approach.

KISA is reorganizing its response framework around the Vulnerability Management Center. The basis for establishing the center is the government’s “Plan to Promote Private-Sector Information Protection to Respond to AI-Based Cyber Threats (draft),” announced in May. The center is responsible for vulnerability management and patch management, and it plays a role in sharing information collected through the KISA Vulnerability Information Portal (KNVD) with relevant institutions and companies.

Bae Seung-gwon, head of the KISA Vulnerability Management Center, said the center is promoting systematic coordination of vulnerability management, which is carried out in a distributed manner. He explained that domestic and international information sharing is also being promoted. He added that, building on this direction, KISA is now strengthening the foundation for rapid response to high-risk vulnerabilities.

Meanwhile, the Forum of Incident Response and Security Teams (FIRST) released a report around June. FIRST forecast that disclosures of Common Vulnerabilities and Exposures (CVE) this year will reach about 66,000.

Last year, 48,448 CVEs were disclosed. That was the highest annual total on record. This year’s projection is about 18,000 higher than last year’s figure.

At the same time, the time from vulnerability disclosure to attack is getting shorter. VulnCheck analyzed 884 vulnerabilities actually exploited in 2025. The results showed that 29% were exploited on the same day the vulnerability was disclosed or before disclosure.

As the pace of patching is not keeping up with the speed at which vulnerabilities are emerging, the gap between attack speed and defense speed is widening. According to Verizon’s “2026 Data Breach Investigations Report (DBIR),” it takes an average of 43 days to fully remediate vulnerabilities listed in the “Known Exploited Vulnerabilities (KEV)” catalog operated by the U.S. Cybersecurity and Infrastructure Security Agency.

In this regard, Bae expressed concern over the surge in vulnerabilities driven by AI, but said it is not yet time to be pessimistic. He said the increase in the number of disclosed vulnerabilities cannot be equated with a rise in software risk, and that the key is not the number of vulnerabilities itself but detecting and responding to risk factors. He added that FIRST analysis also showed that when actual exploitability is taken into account, the response burden does not expand in line with the overall growth rate of CVEs.

Against this backdrop, the center of vulnerability management is shifting from discovery to verification and remediation. KEV is drawing attention as an indicator of whether a vulnerability has been used in real attacks, while EPSS is drawing attention as a system for calculating the likelihood of future exploitation. In addition, methods that set priorities by comprehensively considering internet exposure and asset criticality are also gaining traction.

This photo of Bae Seung-gwon, head of the KISA Vulnerability Management Center, was provided by the Korea Internet & Security Agency. KISA is incorporating AI to speed up vulnerability verification. It believes human analysts inevitably need time to analyze vulnerabilities, and plans to introduce AI into the vulnerability analysis process to improve response speed.

As part of this effort, KISA is using OpenAI’s Trusted Access Program for Cybersecurity (TAC). It is also checking vulnerabilities in government systems through GPT-5.5-cyber.

The systems under review include externally exposed websites of critical infrastructure. Commercial SW widely used in critical infrastructure and open source SW widely used in critical infrastructure are also included in the scope.

The results generated by AI are re-verified by human analysts. After that, the re-verified information goes through a process of being processed so it can be shared externally.

Bae said that out of 10 vulnerabilities identified by AI, only about 5 to 6 are actually judged to be valid. He also said that when humans perform vulnerability detection and analysis, it can take anywhere from a week to as long as a month, whereas AI handles the work in a short time.

AI can play a role in the vulnerability response process by detecting candidate vulnerabilities, supporting PoC efforts to confirm whether they can actually be exploited, and assisting in writing patch code. However, there is a limitation in that it cannot guarantee that AI-generated code will work properly within an individual company’s environment, so it must be separately verified whether the results can be applied directly. For that reason, expert re-verification is necessary.

Bae said it cannot be assumed that PoC and patch code created by AI can be applied directly to a company’s environment. He added that KISA responds by delivering the results to companies only after verification, and that it also checks whether there are any problems in the application process and whether additional technical support is needed.

KISA plans to improve the information-sharing system on the Vulnerability Information Portal and the Boho Korea website. It also aims to build a response framework that connects a single flow of vulnerability discovery, verification, company notification, remediation support, and information dissemination, while concentrating its response capabilities on items with a high likelihood of real-world exploitation.

At the same time, companies need to prepare as well. They must continuously track internet-exposed IT assets and determine patch priorities. They also face the task of tracking vulnerabilities in open source and external libraries included in their products through SBOM-based supply chain management.

Bae noted that while the government is providing support for companies responding to vulnerabilities, there are limits to full government-led execution. Accordingly, he said companies need to establish their own inspection systems and also review how to use AI in security operations.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241783

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.