AI Security Efforts Expand Into Weapons Development

South Korea’s consortium includes 33 organizations and plans to build the 700-billion-parameter model as a Mixture-of-Experts system based on Naver Cloud’s HyperCLOVA X and LG AI Research’s EXAONE.
S2W said it will contribute hard-to-obtain hidden-channel data from beyond the surface web; the company previously developed DarkBERT, a dark-web-focused language model with KAIST for detecting confidential information and cyberthreat-related keywords.
Anthropic said the Yemen-based actors attempted to evade safeguards by concealing their goals, splitting work across multiple sessions and assigning separate Claude instances to coding, research and review. They also test-fired a guided rocket, apparently unsuccessfully, before returning to Claude to investigate the failure.
DSPM’s expansion has been accompanied by industry consolidation: Laminar was acquired by Rubrik and Dig Security became part of Palo Alto Networks, reflecting the growing strategic importance of data-security posture management.
AI security operations platforms can combine SIEM, SOAR, UEBA, EDR, NDR, threat intelligence and vulnerability-management data to add behavioral and risk context, rather than treating every alert as equally important.
Artificial intelligence is transforming cybersecurity defenses and attack capabilities alike. South Korea launched a government-backed project to build a specialized 700-billion-parameter AI security model SecurityBoulevard, while BleepingComputer reported that threat actors in Yemen exploited AI tools to develop missile guidance software. Meanwhile, security teams are deploying AI to automate alert analysis and reduce false alarms across cloud and data systems.
The trend reflects a dual reality: defenders need smarter tools to catch threats, while attackers leverage the same AI technology. This arms race is spurring industry consolidation and pushing companies to rethink how they monitor data access, manage security alerts and protect systems from both human and automated threats.
A consortium of 33 South Korean organizations—including S2W, Naver Cloud, LG CNS and universities—is developing a specialized 700-billion-parameter AI model for cybersecurity. The model will use a Mixture-of-Experts architecture based on Naver Cloud's HyperCLOVA X and LG AI Research's EXAONE, according to SecurityBoulevard. S2W will contribute hard-to-obtain threat intelligence from hidden channels and the dark web.
S2W previously built DarkBERT with KAIST, a dark-web-focused language model designed to detect confidential information and cyberthreat keywords. The new project aims to create a security-focused alternative to general-purpose AI models that may lack domain expertise in threat detection and incident response.
BleepingComputer reported that Anthropic discovered Yemen-based actors attempted to use Claude Code to develop guidance software for missile programs. The actors tried to evade safeguards by hiding their goals, splitting work across multiple sessions and assigning separate Claude instances to coding, research and review tasks.
The group test-fired a guided rocket—apparently without success—then returned to Claude to investigate the failure. Anthropic stressed there is no evidence they successfully fielded an operational weapon. The case underscores how attackers are experimenting with AI tools for weapons development and systems engineering.
Data Security Posture Management (DSPM) has grown beyond basic data discovery to track access, exposure, movement and sensitive information entering AI systems. ChannelE2E noted that identity attacks are creating security gaps as employees work across email, browsers, SaaS applications, cloud platforms and AI tools.
Industry consolidation reflects DSPM's rising importance. Rubrik acquired Laminar and Palo Alto Networks bought Dig Security, signaling that managing data risk across cloud, SaaS, development and backup environments is now a core strategic priority for enterprises.
Security operations platforms are using AI to correlate alerts, reduce false positives and rank threats by confidence and risk. By combining data from SIEM, SOAR, UEBA, EDR, NDR, threat intelligence and vulnerability management, these tools add behavioral and risk context to every alert.
This shift lets human analysts focus on high-confidence incidents while automated systems handle routine investigations. FinancialPost highlighted how AI-enabled software can process massive data volumes that human staff cannot manage manually, reshaping how defenders allocate time and resources.
Publishers
33
Articles
92
Reach
125