Artificial intelligence is helping attackers analyze and exploit software vulnerabilities, according to a new report from Google Threat Intelligence Group (GTIG). The report says the main change is not a surge in zero-day attacks, but faster exploitation of flaws that are already known.
GTIG counted 5,045 newly discovered flaws in January 2026 and 10,740 in August. It also reported that the average number of vulnerabilities exploited in the wild rose from 10.5 per month in 2025 to 18 per month during the period examined in 2026. Zero-day exploitation increased more modestly, from 8 cases a month in 2025 to 11 a month in 2026. Google said exploitation of high-risk flaws doubled year over year.
The report suggests threat actors may be using large language models and other AI tools to compare product versions, patches, vulnerability disclosures and proof-of-concept code, helping them weaponize “n-day” flaws. These are vulnerabilities known before exploitation. GTIG also said AI can help defenders prioritize findings: 50% of vulnerabilities discovered with AI led to remote code execution, compared with 26% across the broader vulnerability landscape.
As one example, Google cited CVE-2026-1731, a command-injection flaw in BeyondTrust products found by a third-party AI research agent. GTIG said attackers began exploiting it within days of public disclosure, in campaigns involving privilege escalation, data theft and malware deployment.
Google expects vulnerability discovery and exploitation to keep growing in the short to medium term. The report argues that defenders will need threat-intelligence-driven prioritization as attackers increasingly automate analysis and exploit development.
Comments
0No comments yet. Be the first to comment.