As hacking using AI spreads, there are growing calls that cyber security strategies also need to change. The rise of so-called Offensive Security, which approaches security from an attacker’s perspective rather than a defender’s, is drawing attention.
In the past, security solutions built around a defensive stance led the market. Experts say that as AI spreads and cyber attacks speed up sharply, security must also be viewed through an attacker’s eyes, including through simulated hacking and penetration tests.
The emergence of keywords such as COST (Continuous Offensive Security Testing) and CTEM (Continuous Threat Exposure Management) is not unrelated to this.
Moves by the industry toward offensive security solutions are also accelerating. Kwon Young-mok (권영목), chief executive of Pago Networks, said concerns are growing that hackers armed with AI models such as Mythos can find unpatched vulnerabilities and attack immediately. He said this is speeding up efforts in the security solutions market to use AI to carry out ongoing simulated hacking and penetration tests before attackers get in.
ㆍPiolink "With AI hacking spreading, a layered defence system should be built with CTEM and web application firewalls" ㆍ[DT People] After Mythos, the centre of gravity in security shifts from products to operations...competing with SOC as a service"
Dutch security startup Hadrian Security, which provides an AI agent that finds vulnerabilities attackers can actually exploit, raised 36 million euros in funding. Hadrian highlights as a differentiator that it combines continuous exposure management and agentic penetration testing on a single platform.
ㆍ"Seeing through an attacker’s eyes"...Security startup Hadrian raises 36 million euros
After AI-based tools were identified as having been used in hacking attacks targeting South Korea’s financial sector, South Korea has also entered the direct sphere of impact of AI-driven hacking. Security experts view AI hacking as likely to have already been attempted widely. The case drew more attention because major financial companies were included among the targets. Foreign media as well as South Korean media covered it prominently, as cyber attacks using AI-based penetration testing tools hit the financial sector, which holds large amounts of sensitive information.
ㆍAI hacking, armed with speed, hits South Korea...Will security strategy reform gain traction ㆍBeyond banks to savings banks and capital firms...financial sector on 'hacking alert' ㆍ[National Audit 2026] "You check only 3 months and say there is no issue?"...financial sector hacking inspections under fire ㆍFinancial sector hacking spreads on all fronts...28 attacking IPs identified, police investigation begins
Analyses by domestic and overseas security companies are also being released one after another. SK Shieldus said that based on information disclosed so far, the recent incidents in the financial sector are closer to cases where AI automated and advanced existing attacks, rather than cases where AI created new attack techniques. Global security company CrowdStrike did not point to a specific organisation as the attacker, but said its analysis suggests a Chinese-language user and that financial motives are likely.
ㆍ"Recent financial sector AI hacking automated and advanced existing attack techniques"...SK Shieldus analysis ㆍCrowdStrike analyses AI hacking that hit Korea’s financial sector..."Appears to be a Chinese-language user seeking financial gain"
Security experts are also voicing a range of views on responding to AI hacking.
ㆍ"Talk of an 'AI rampage' hides the real security issues...Controls must be 마련ed outside the model" ㆍAI hacking threatens the foundations of internet security through speed alone ㆍ"Zero trust security remains valid in the AI era...but it must be properly implemented" ㆍ[Tech Insight] "AI hackers target logical flaws, not code"
It also summarised moves and issues involving domestic and overseas companies around security.
SK Telecom launched a "sovereign AI cyber security consultative body" involving Upstage, domestic security companies and universities, and signed a memorandum of understanding for cooperation on AI information security technologies for the initiative. Integrated security firm SGA Solutions will supply in South Korea Illumio’s micro-segmentation solution from zero trust security company Illumio. Logpresso will expand the monitoring scope of its Security Information and Event Management (SIEM) platform to include corporate use of generative AI. It first released an app linking to ChatGPT Enterprise that integrates and analyses generative AI usage records with existing security logs.
ㆍSKT and Upstage launch 'sovereign AI cyber security consultative body'...domestic security firms and universities also participate ㆍSGA Solutions to supply Illumio micro-segmentation security solution in South Korea ㆍLogpresso expands SIEM monitoring scope to generative AI...starting with ChatGPT Enterprise
SK Shieldus obtained Amazon Web Services (Amazon Web Services, AWS) Security Competency in Threat Detection and Response (TDR). Ontology-based enterprise AI company InfoSys launched a graph-based AI security solution called GOS (Graph Optimized Security) and supplied it to a major domestic semiconductor company. ㆍSK Shieldus obtains AWS TDR Security Competency...expands cloud security business ㆍInfoSys launches AI security solution GOS...supports large-scale log analysis using LLMs
Red Hat and IBM said that through Lightwell, a security infrastructure they provide as part of efforts to offer safer open-source software, they found more than 400 previously unknown vulnerabilities in Java libraries and took corrective action.
Anthropic expanded and reorganised its cyber security access programme and enabled more security stakeholders to use its top-tier Claude model. SailPoint said at Navigate 2026 in Austin, Texas, that it is reshaping its platform so that access privileges for people and agents are managed under a single policy framework and incorrect access is blocked as soon as it occurs.
ㆍRed Hat and IBM take corrective action on more than 400 unknown open-source vulnerabilities through Lightwell ㆍAnthropic expands and reorganises cyber security programme...allows all participants to use Mythos ㆍSailPoint "There are 100 times more AI identities than people"