Shin Eun-su, principal security specialist solutions architect at AWS Korea. [AWS Korea]
Shin Eun-su, principal security specialist solutions architect at AWS Korea. [AWS Korea]

AI is accelerating the pace of cyberattacks. As high-performance AI models take on tasks such as detecting zero-day vulnerabilities and generating exploit code, the time it takes for a vulnerability to be weaponized has shrunk from years to roughly a single day. Corporate patch cycles still average about a month. Amid the widening gap between attack and defense speeds, Amazon Web Services said security frameworks must shift toward real-time verification and automation.

AWS held an "AWS Security 101" press briefing at its Korea office Tuesday, outlining how the spread of high-performance AI is reshaping the threat landscape and what organizations can do to respond.

Shin Eun-su, principal security specialist solutions architect at AWS Korea, said the rise of high-performance AI could upend conventional notions of time in cybersecurity. Finding vulnerabilities and turning them into working exploit code were once the domain of a small number of specialists, but AI has made that process far easier and faster. "Finding a vulnerability and building an executable program based on it has become both easy and fast," Shin said.

The core problem is the growing gap between attack speed and defense speed. According to AWS, the average time to exploit a vulnerability fell from 2.3 years in 2018 to five days in 2024, and stands at roughly 20 hours in 2026. Organizations still take an average of 32 to 38 days to deploy a patch. In recent benchmarks, AI-assisted exploit success rates reached as high as 87 percent. The figures illustrate how AI is simultaneously enabling security automation and lowering the barrier to entry for attackers.

Shin identified speed and scale as the defining characteristics of the high-performance AI threat. "The biggest problem with high-performance AI threats is that they are becoming far faster and more numerous," he said. "Organizations need tools that can keep up with threats that are accelerating and multiplying at this rate."

Shin Eun-su, principal security specialist solutions architect at AWS Korea, presents at the "AWS Security 101" press briefing at the AWS Korea office on Tuesday. [Park Hye-rim]
Shin Eun-su, principal security specialist solutions architect at AWS Korea, presents at the "AWS Security 101" press briefing at the AWS Korea office on Tuesday. [Park Hye-rim]

AWS outlined automated verification and layered defense as its core response strategies. The company applies automated reasoning technology — which mathematically verifies whether security policies and network configurations are safe — across its security services, and operates large-scale threat detection infrastructure. AWS's security organization analyzes more than 400 trillion network flows per day, while Amazon GuardDuty monitored an average of 8.8 trillion events per hour in the second half of 2025. AWS protects more than 1 billion EC2 instances and, in 2025, blocked more than 300 million malicious encryption attempts targeting customer data stored in Amazon S3.

Security operations automation was also presented as a key strategy. AWS introduced "AWS Continuum," a framework that automates the entire security lifecycle — from vulnerability discovery and prioritization to verification and remediation. The approach uses agent-based workflows to connect steps between detection and response, including penetration testing, code vulnerability analysis and threat modeling, with the goal of accelerating security response times.

Henge, a Japanese SaaS security firm, adopted the AWS Security Agent and cut its security validation period by more than 90 percent, reducing penetration tests that previously took weeks to a matter of hours. "When facing an enormous number of vulnerabilities and fast-moving attacks, it is better to proactively eliminate the conditions that allow patches to become necessary in the first place, rather than patching efficiently after the fact," Shin said.

AWS urged organizations to adopt two practices: "shift left" security, which integrates security into the development lifecycle from the outset, and continuous automated security verification. Because AI is raising the speed of both offense and defense, security must move away from a reactive, after-the-fact model toward one centered on real-time verification and automation.


rim@heraldcorp.com