메뉴
BL
Wired AI • 6일 전

AI 둔화론은 잊어라, 취약성 폭발은 이미 시작됐다

IMP
8/10
핵심 요약

AI를 활용한 취약점 발견이 가속화되면서 올해 기록된 CVE 수가 이미 작년 전체의 두 배에 달하는 등 '취약성 쓰나미'가 현실화되고 있습니다. Microsoft, Oracle, Google Chrome 등 주요 업체의 패치 건수가 사상 최고치를 경신하고 있으며, 인력 부족에 시달리는 보안팀과 오픈소스 유지보수 자원봉사자들에 대한 부담이 급증하고 있습니다. 전문가들은 취약점 발견 자체보다 패치 속도가 이를 따라가지 못하고 공격자들이 AI로 신규 취약점을 발견하는 것이 진짜 위험이라고 지적합니다.

번역된 본문

「Kernel Panic」 뉴스레터 창간호에 오신 것을 환영합니다! Lily Hay Newman과 Matt Burgess가 프라이버시와 디지털 보안의 새로운 세계에서 전해드리는 주간 뉴스레터입니다. 매주 받아보시려면 여기에서 구독하세요.

AI 종말론자들이 최근 한 가지 최악의 시나리오를 다른 것으로 바꾸어, 소프트웨어 취약점 대재앙 가능성은 접어두고 향후 10년 내 악성 AI가 대량 인류 사망을 일으킬 가능성에 집중하고 있습니다. 그러나 AI 업계 지도자들이 최첨단 모델 개발의 협력적 둔화를 논의하는 동안, 오픈 웨이트 모델을 포함한 주류 AI 제품의 기존 범용 기능 덕분에 사이버보안의 대격변 한 측면은 이미 도래했습니다.

AI를 활용해 발견된 취약점의 해일은 최근 몇 달간 오히려 가속화되었으며, 인력이 부족한—그리고 여전히 인간인—IT 및 보안팀에 더 큰 부담을 안기고, 중요한 오픈소스 소프트웨어를 유지보수하는 자원봉사자들에게도 무리를 주고 있습니다. 연구자들은 AI 기반 버그 헌팅 시대 이전에도 방대한 취약점을 발견·공개해왔지만, 최근의 급증은 뚜렷합니다.

Microsoft는 지난주 이번 달에만 974건의 CVE 패치를 배포해 사상 최고 기록을 세웠다고 밝혔습니다. (CVE, 즉 공통 취약점 및 노출은 확인된 소프트웨어 결함을 뜻하는 사이버보안 용어입니다.) 7월에는 Oracle이 1,448건의 패치를 배포했는데, 이는 2025년 7월의 309건과 대비됩니다. Google Chrome의 6월 두 번의 주요 버전 릴리스에는 1,072건의 패치가 포함되었는데, 이는 이전 23번의 대형 릴리스 전체에 배포된 취약점 수정 총량보다 많은 수치입니다. Mozilla는 4월에 Anthropic의 Mythos 모델을 활용한 버그 헌팅 스프린트 한 차례에서만 Firefox에서 271건의 취약점을 발견했다고 밝혔습니다.

전반적으로, Empirical Security의 연구 책임자이자 CVE 분석 프로젝트 cve.icu를 운영하는 RogoLabs의 창립자인 Jerry Gamblin에 따르면, 이번 주 수요일 기준 놀랍게도 66,401건의 CVE가 기록되었습니다. 작년 9월 16일까지 cve.icu에 기록된 총 CVE는 33,512건으로, 현재 총량의 절반에 가깝습니다. OpenAI가 ChatGPT 첫 버전을 출시한 해인 2022년 전체에는 cve.icu에 25,000건의 CVE가 기록되었습니다.

보안 및 AI 연구자들 사이에서는 이러한 급증과 AI가 사이버보안에 미치는 다른 영향이 재앙적일지, 아니면 기존의 역학과 도전을 증폭시키는 것에 그칠지에 대해 의견이 분분했습니다. 일부는 느린 패치 적용과 사이버보안 투자 부족이 AI 시대 이전부터 공격자에게 이미 많은 우위를 제공해 해킹 참사를 낳았다고 지적했습니다. 하지만 취약점 발견 건수가 계속 증가하고 논의가 덜 이론적으로 되면서 양측의 입장은 어느 정도 가까워진 것으로 보입니다.

"과장된 이야기라고 생각하지 않는다"고 Gamblin은 업계 전반의 취약점 발견 폭발에 대해 말합니다. "내가 반박하고 싶은 것은 숫자가 커지는 것 자체가 피해라는 발상이다. CVE가 더 많다는 것은 취약점이 더 많다는 뜻이 아니다. 알려진 취약점이 더 많다는 뜻이며, 이는 대부분 시스템이 제대로 작동하고 있다는 것이다."

하지만 우려는 방대한 취약점 발견이 개발자가 패치를 감당하지 못하고, 소프트웨어 사용자가 충분히 빠르게 패치할 수 없으며, 더 많은 공격자가 AI를 이용해 스스로 신규 취약점을 발견하면서 사이버공격이 격화되는 결과로 이어질 것이라는 점입니다. 영국 국가사이버보안센터(NCSC)의 표현대로 "취약점을 발견하는 것만으로는 보안이 전혀 개선되지 않는다."

당장은 AI가 버그 발견을 가속하는 것과 AI가 방어자를 돕는 것 사이에 적어도 불안한 균형이 유지되고 있다고 많은 연구자들이 말합니다. "업계와 마찬가지로 (공격) 행위자들도 '어디에 AI를 쓸까'를 파악하려 하고 있다"고 Cisco Systems의 위협 인텔리전스 총괄인 Matthew Olney는 말합니다.

상황이 계속 변화하는 가운데, 규제든 업계 합의든 어떤 형태의 AI 둔화가 있다면 어쩌면—희망적으로—AI가 인류 대량 절멸 사건을 일으키는 것은 막을 수 있을지 모릅니다. 하지만 이미 도래한 취약점 쓰나미는 막을 수 없습니다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story Welcome to the inaugural edition of Kernel Panic ! A weekly newsletter by Lily Hay Newman and Matt Burgess from inside the new world of privacy and digital security. To receive this newsletter in your inbox each week, sign up here . AI doomers have recently traded one worst-case scenario for another, putting aside a potential software vulnerability apocalypse to focus on the possibility of rogue AI causing mass human death in the next decade. As AI leaders consider a cooperative slowdown on frontier model development, though, one aspect of the cybersecurity sea change has already arrived thanks to existing, broadly available capabilities in mainstream AI products, including open weight models. A tidal wave of vulnerabilities uncovered using AI has only accelerated in recent months—piling more pressure on under-resourced, and very human, IT and security teams and straining volunteers who maintain crucial open source software. Researchers found and disclosed a vast array of vulnerabilities before the rise of AI-enhanced bug hunting as well, but the recent surge is clear. Microsoft said last week that it has issued patches for 974 CVEs so far this month, setting a new record. (CVEs, or common vulnerabilities and exposures, is cybersecurity jargon for confirmed software flaws.) In July, Oracle shipped 1,448 patches compared to 309 in July 2025 . Google Chrome’s two major version releases in June included 1,072 patches, more than all of the vulnerability fixes shipped in the prior 23 big releases combined. And Mozilla said in April that it found 271 vulnerabilities in Firefox during one bug hunting sprint using Anthropic’s Mythos model. Across the board, there have been a stunning 66,401 CVEs recorded as of Wednesday this week, according to Jerry Gamblin, the head of research at Empirical Security and founder of RogoLabs, which runs the CVE analysis project cve.icu . By September 16 last year, cve.icu had logged a total of 33,512 CVEs—almost half the current total. For all of 2022, the year OpenAI launched its first version of ChatGPT, cve.icu recorded 25,000 CVEs. Among both security and AI researchers, experts have been divided about whether this spike and other impacts of AI on cybersecurity will be catastrophic or instead magnify existing dynamics and challenges. Some have pointed out that slow patch adoption and lagging investment in cybersecurity broadly already gave attackers many advantages that led to hacking disasters before the rise of AI. But as vulnerability discovery numbers have continued to rise, and the discussion has become less theoretical, the two sides have seemed to move a bit closer. “I don’t think it’s overblown,” Gamblin says of the apparent explosion in vulnerability findings across the industry. “What I would push back on is the idea that a bigger number is itself the harm. More CVEs is not more vulnerability. It's more known vulnerability, which is mostly the system working.” The fear, though, is that vast vulnerability discovery will mean developers getting outpaced on patching, software users who can’t patch fast enough, and an array of escalating cyberattacks fueled by more attackers discovering novel vulnerabilities on their own using AI. As Britain’s National Cyber Security Center puts it , “Just finding vulnerabilities does nothing to improve your security.” For now, many researchers tell us that there is at least a tenuous balance between AI accelerating bug discovery and AI aiding defenders. “Actors, just like industry, are trying to figure out, ‘where do I use AI?’” says Matthew Olney, director of threat intelligence at Cisco Systems. As the situation continues to evolve, an AI slowdown of whatever form—be it regulation or an industry accord—could perhaps/hopefully prevent AI from carrying out a mass human extermination event, but it cannot stop the vulnerability tsunami that has already arrived as a result of existing AI tools. As RogoLabs Gamblin puts it, “Discovery scales with compute. Remediation scales with people—and people are the part you can't buy more of in a quarter.”