[Photo: Reve AI]

[DigitalToday reporter Chi-gyu Hwang] Discussion is active over how to respond to new security threats raised by the spread of AI. Company-to-company alliances are also taking shape, with participation expanding beyond security to include semiconductor and platform firms.

The Nvidia-led Open Secure AI Alliance (OSAA) set up its first working group, SAFE (the Shared AI Findings Exchange), and released proposals on responding to AI security incidents a week after its launch. The proposals include a way to confidentially report AI cybersecurity incidents, procedures to notify affected parties and a post-incident analysis system focused on learning rather than assigning blame. It did not present an immediate major technological change, but focused on first establishing common industry response rules.

Nvidia-led Open Secure AI Alliance releases proposals on responding to AI security incidents

After an AI agent that OpenAI was testing broke out of control and hacked Hugging Face, an open-source AI model sharing platform, Hugging Face CEO Clem Delangue said disclosure of hacks targeting AI companies should be mandatory. He said a system to transparently disclose incidents is more important than a way to prevent the release of powerful AI models.

Hugging Face CEO: After OpenAI-linked hacking incident, AI firms should be required to disclose hacks

Concerns also appear to be growing that advanced AI could be misused, or that AI could slip out of control and cause unintended incidents. Two independent testing organisations additionally confirmed cases in which top models from Anthropic and OpenAI tried to breach third-party systems last month, and some actually succeeded. Anthropic and Meta AI models were also shown hacking during tests.

OpenAI’s Hugging Face hack...has Pandora’s box been opened? Anthropic AI model also accessed the internet during testing and hacked 3 companies Meta AI model also hacked after breaking control, third after OpenAI and Anthropic "Additional 19 cases confirmed of attempts to breach real systems during tests by Mythos5 and GPT-5.6 Sol"

Security firm CrowdStrike, in its '2026 Threat Hunting Report', said artificial intelligence is becoming a direct target of attacks beyond being an attack tool, and that the pace of vulnerability exploitation has accelerated to the scale of hours. Gartner forecast that by 2029 most personal data breach incidents would stem not from direct leaks of personally identifiable information (PII) but from inferences that AI generates about individuals.

"Vulnerability exploitation concentrated within 48 hours"...CrowdStrike report "Watch for personal information breaches caused by AI inference"...Gartner forecast

There are also growing concerns about attacks targeting security vulnerabilities in AI itself. Since the incident in which an OpenAI AI agent hacked Hugging Face during a test, cases have continued to emerge showing that AI tools from major companies also have vulnerabilities.

Security vulnerabilities spread across well-known AI tools...2 cases also found in Microsoft Copilot

The article also summarises moves and issues involving companies in and outside South Korea around security.

LG Uplus acquired managed detection and response (MDR) solution specialist Pagonetworks. It plans to internalise Pagonetworks’ threat detection, analysis and response capabilities to advance its company-wide security system and expand its security business for corporate customers. LG Uplus’ integrated account management service, AlphaKey, obtained the cloud security assurance program (CSAP) software-as-a-service (SaaS) standard grade.

LG Uplus takes over Pagonetworks...advances company-wide security system LG Uplus’ AlphaKey becomes first domestic IDaaS to obtain CSAP

Remote support specialist RSUPPORT will work with cyber-physical system (CPS) security specialist NNSP to jointly identify a remote support business model that can be applied to the National Network Security Framework (N2SF) and industrial control networks. Aton signed a business agreement with the Korea Internet & Security Agency (KISA) as a specialist solution provider for a system that blocks malicious texts in advance. It will supply the system to internet text-message sending businesses and issue adoption confirmation documents required to register as a value-added telecommunications service provider. Naru Security will carry out KISA’s project to detect affected companies and diagnose vulnerabilities in regional intrusion incidents. Epson Korea signed a memorandum of understanding with security solutions firm Nexpot Solution to expand the anti-counterfeit security label market and develop high-value label solutions. Offensive cybersecurity firm Theori supplied its AI-based black-box penetration testing solution, Xint Web, to Woori Financial Group.

RSUPPORT and NNSP cooperate to develop remote support business model targeting N2SF and control networks Aton signs agreement with KISA...supports specialist solution for blocking malicious texts in advance Naru Security to carry out KISA project on detecting affected firms and diagnosing vulnerabilities in regional intrusion incidents Epson cooperates with Nexpot Solution to expand anti-counterfeit security label market Theori supplies AI penetration testing solution Xint Web to Woori Financial Group

Korea Quantum Computing (KQC) signed a strategic memorandum of understanding with German cybersecurity and information management software firm Data-Warehouse GmbH and will enter the post-quantum cryptography (PQC) migration platform business. Network security firm Xgate is strengthening its AI strategy with the goal of reinforcing competitiveness in areas it has done well, rather than using AI to target areas it has not previously pursued. ESTsecurity received the Amazon Web Services (AWS) Partner Network (APN) Select Tier partner designation and is moving into cloud and AI security business.

Korea Quantum Computing partners with German security firm...steps up PQC migration platform business [DtwoPeople] "Apply AI to security areas we do well...advance network security in line with zero trust" ESTsecurity cooperates with AWS...steps up cloud and AI security business

Amazon Web Services (AWS) is integrating its code vulnerability checking service, AWS Continuum, into AI coding tools from Anthropic and OpenAI. Users can now check for vulnerabilities directly inside OpenAI and Anthropic coding tools. F5 introduced F5 AI Guardrails, an AI-native solution that integrates with NVIDIA NeMo Guardrails and provides its enterprise-grade AI security capabilities to AI applications at the operational stage. Palo Alto Networks released network security research results and new products for the era of frontier AI. ServiceNow introduced 6 autonomous security products and a lineup of AI security agents after acquiring Aamis and Beza. The products support progressing from vulnerability handling and incident response through to closure without analysts having to intervene at each step.

AWS links Continuum to OpenAI and Anthropic AI coding tools...checks vulnerabilities inside the editor F5 AI Guardrails integrates with NVIDIA NeMo Guardrails...strengthens runtime security for enterprise AI apps Palo Alto Networks: "AI exploits vulnerabilities immediately; virtual patching is the answer" ServiceNow unveils 6 autonomous security products...from vulnerability response to compliance

Tera Security launched Prevention, an automatic firewall rule generation function that blocks attacks verified to work in practice by AI agents.

Tera Security launches automatic firewall rule generation function to block verified exploits

Keyword

#Nvidia #Open Secure AI Alliance #Hugging Face #OpenAI #Gartner
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.