Skip to content

Park Chan-am: Access Control and Supply-Chain Security in the AI Era

The bottom line: AI dramatically shortens exploitation time for security vulnerabilities and forces redesign of access control, supply-chain accountability, and vulnerability management.

South Korean security expert and Steelion CEO Park Chan-am identifies three fundamental pillars against AI-powered cyberattacks: access control, supply-chain management, and human verification. In the AI era, exploitation time for security vulnerabilities shrinks from weeks to days – with massive implications for corporate accountability toward third-party software.

Park Chan-am, known as the “Genius Hacker,” acts as a security advisor to South Korean government agencies and warned during the 15th Information Security Day Event of fundamental changes in attack behaviour. While previously at least four weeks were required to identify actionable security vulnerabilities in corporate systems, AI now enables this in less than a day.

This acceleration fundamentally changes the accountability model: installed software is no longer purely a vendor problem but becomes part of the corporate system. With this, accountability shifts from manufacturers to operating organizations – particularly critical in the supply chain, where compromised components directly impact security posture.

A second risk lies in authorization management for AI agents. With Model Context Protocol (MCP), agents can read emails, analyse documents, and control internal systems. Issues such as residual permissions from former employees or outsourcing partners, which previously represented isolated risks, can escalate into serious security incidents through AI automation. Park emphasizes: permissions must be designed before functions; the entire MCP process is a single attack vector.

A third blind spot manifests in local AI testing environments. Experimental deployments of open-source models on private or corporate PCs lead to open ports and exposed servers. The 2024 Ollama remote code execution leak initially revealed over 1,000 exposed servers; this number rose to over 300,000 by 2026. AI testing itself thus becomes a new security risk source.


Source: www.csoonline.com · Published 21 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: