AI can be used to block security threats, but concerns are also growing that AI could threaten security beyond human control. Those concerns gained strength after it was disclosed that an AI agent OpenAI is testing broke out of a controlled environment and hacked Hugging Face, an open-source AI model sharing platform.
The OpenAI agent in trial operation was also confirmed to have breached customer systems at Modal Labs in the process of attacking Hugging Face. The OpenAI agent first broke into an isolated test environment, or sandbox, built at Modal Labs and then used it as a foothold to carry out a large-scale attack on Hugging Face.
• OpenAI AI agent escapes controls, also breaches Modal Labs customer accounts
There are also warnings that Anthropic’s Claude could escape a controlled environment. Security firm Accomplish AI demonstrated that the Claude AI agent could use a Linux vulnerability to break out of a virtual machine and access Mac operating system files.
• After OpenAI, Anthropic’s Claude also raises concerns about escaping controlled environments
Ransomware targeting AI models has also emerged. U.S. security company Sysdig said the same attacker breached internet-exposed Langflow servers twice, and used dedicated ransomware for AI models, dubbed ENCFORGE, in the second attack.
• Ransomware targeting AI models emerges; concerns grow over soaring recovery costs as training weights are encrypted
Cases where AI plays a meaningful role in security are also continuing to emerge. Anthropic drew attention after finding a fundamental weakness in HAWK, a candidate post-quantum cryptography (PQC) algorithm, using its AI model Mythos.
• Anthropic: AI capabilities for cryptanalysis are growing; Mythos finds weakness in PQC algorithm HAWK
Competition is also intensifying over security-focused AI models that are aimed at helping identify software vulnerabilities and fix problems.
• From vulnerability detection to reasoning, security-focused AI models are pouring out • Microsoft unveils its first cybersecurity-focused model and deploys an agentic security platform
Tae-soo Kim (김태수), Microsoft’s vice president of agentic security at its headquarters, said at Codegate 2026, an international hacking defense competition and security conference, that large language models show very strong capabilities while also making basic mistakes. He stressed that distinguishing which problems to entrust to AI and which to leave to human judgment is key to using AI.
• "Finding and fixing security vulnerabilities with AI is already reality; using multiple AI models is more effective"
The Open Secure AI Alliance, a coalition that develops and shares open technologies, techniques and tools to protect software and agents in the AI era, will be launched led by Nvidia and global companies.
• Global firms to launch Open Secure AI Alliance; SKT and Naver also join
Other developments and issues involving domestic and overseas companies around security were also compiled.
ITCEN PNS obtained KCMVP certification after applying a post-quantum cryptography-based hybrid encryption method to its cryptographic module EdgeCrypto v4.2. HancomWITH, which serves as the holding company of Hancom Group, signed a supply contract with NH NongHyup Property & Casualty Insurance for its face authentication solution Hancom Auth. JSecurity, a Japanese affiliate of JiranJigyo Group, launched its domain-based attack surface management and dark web data leak detection solution SafeIntelligence in South Korea. Fasoo AI will expand support in its multi-cloud data security posture management solution, Fasoo DSPM, for cloud storage and SaaS applications. KCC Information & Communication signed a master distribution agreement with global cybersecurity company Kaspersky and is moving to target the domestic enterprise market.
• ITCEN PNS obtains KCMVP certification with PQC-based hybrid cryptographic module • HancomWITH to supply face authentication solution Hancom Auth to NH NongHyup Property & Casualty Insurance • JSecurity launches domain-based attack surface management and dark web data leak detection solution • Fasoo AI expands Fasoo DSPM support, including OneDrive, SharePoint, Outlook and Slack • KCC Information & Communication signs master distribution deal with Kaspersky, targeting EDR, OT and Linux server security
Data security company Cyera will acquire Oasis Security in a deal worth $1 billion. Cyera plans to integrate Oasis Security technology into its unified identity and data security platform after the acquisition. Global AI data cloud company Snowflake unveiled Cortex AI Gateway, which it said will strengthen AI agent security and provide centralized visibility and control over AI usage costs.
• Cyera to acquire Oasis Security for $1 billion to expand AI agent security • Snowflake launches Cortex AI Gateway, expanding AI security business • Okta to acquire Permiso to strengthen AI identity security capabilities