[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f76HNZn0C-2snKFw2q9kjg5_AnPLUaUK8KBJAgVCI_Yk":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"d50d5458-712f-4b5d-a1fb-579a7d2ce452","Google: AI Is Changing the Pace and Profile of Vulnerability Discovery","google-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery-11a943","Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post Google: AI Is Changing the Pace and Profile of Vulnerability Discovery appeared first on SecurityWeek.","Google Threat Intelligence Group (GTIG) reports a doubling of disclosed vulnerabilities and exploited vulnerabilities in 2026. They observe that AI is significantly changing the pace and profile of vulnerability discovery, with AI-discovered flaws showing a higher propensity for remote code execution (RCE) and memory corruption issues. While zero-day exploitation has increased marginally, the trend suggests threat actors are leveraging AI to more efficiently weaponize n-days.","Google: AI is accelerating vulnerability discovery and exploitation, with AI-found flaws more likely to be RCE.","The number of vulnerabilities disclosed each month doubled in 2026, and the monthly average of vulnerabilities exploited in the wild nearly doubled, according to a new report from Google Threat Intelligence Group (GTIG). Analyzing disclosures from January 2025 through August 2026, GTIG found that monthly disclosures rose from 5,045 in January 2026 to 10,477 in July, peaking at 10,740 in August. “We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered,” GTIG says. The researchers caution that raw volume can be misleading, as automated CVE assignment in open source ecosystems can inflate the numbers. Vulnerabilities whose description mentions the Linux kernel alone generated roughly 5,000 CVEs between January and August, with no in-the-wild zero-day exploitation observed. High-risk disclosures, based on GTIG’s own ratings rather than CVSS, grew 167%, from 131 in January to 350 in August. In addition, GTIG recorded 141 distinct exploited vulnerabilities in the first eight months of 2026, more than the 127 seen in all of 2025. That’s an average of 18 per month, up from 10.5 last year. Still, only 0.23% of this year’s disclosed vulnerabilities, roughly one in 431, were observed being exploited.Advertisement. Scroll to continue reading. Zero-day exploitation increased only marginally, from an average of eight per month in 2025 to 11 per month in 2026, although the count jumped to 22 in August. Zero-days made up 62% of the vulnerabilities exploited between January and August. GTIG suggests that the growth in exploitation came primarily from n-days. Exploitation of high-risk vulnerabilities also more than doubled, from 28 in 2025 to 75 in the first eight months of 2026. “It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days,” the report reads. Vulnerabilities that GTIG identified as likely discovered by AI between January and August show a different risk profile. Of these, 39% were rated low-risk and 58% medium-risk, compared to 69% and 28%, respectively, for non-AI vulnerabilities. GTIG says this likely reflects how research programs deploy AI agents, tasking them with auditing critical infrastructure and sensitive privilege boundaries with a focus on higher-impact findings. Half of the AI-discovered vulnerabilities result in remote code execution, compared to 26% of non-AI vulnerabilities. According to GTIG, this likely stems from AI models’ ability to find memory corruption and logic flaws that traditional static analyzers miss. GTIG has also confirmed in-the-wild exploitation of AI-discovered vulnerabilities, though it describes this as an early indicator rather than an established trend. One example is CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, discovered autonomously by the Hacktron AI research agent. One threat cluster exploited it within four days of public disclosure, and five more followed within seven days. Disclosures of vulnerabilities in AI systems themselves are also rising. GTIG tracked 2,076 AI-related CVEs between January 2025 and August 2026, including more than 1,500 this year, roughly half of which affect AI orchestration frameworks. Only a handful of the 2,076 have been confirmed as exploited in the wild, including flaws in LiteLLM and Langflow. GTIG has not yet observed zero-day exploitation of AI infrastructure. “GTIG expects that rates of vulnerability discovery and exploitation are likely to continue to increase in the short to medium term,” the report reads. Related: High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL Related: WatchGuard Patches Critical Fireware OS Code Injection Vulnerability Related: Chrome, Firefox Updates Patch Over 100 Vulnerabilities Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data LeaksPentagon Personnel Agency Data Breach Impacts 3 Million PeopleOpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier TrainingApple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ Nvidia Unveils AI Agent Safety Platform With Hardware-Based WatchdogCitrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugMicrosoft SharePoint Flaw CVE-2026-65660 Now Exploited in AttacksNorth Korea Suspected in $351 Million Bitget Crypto Heist Latest News WatchGuard Patches Critical Fireware OS Code Injection VulnerabilityGovernment, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day AttacksChrome, Firefox Updates Patch Over 100 VulnerabilitiesAnthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking LawsuitRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come ForwardHigh-Severity Vulnerabilities Patched in OpenSSL, WolfSSLTrump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveDavid Cass has joined Grayscale Investments as Chief Risk Officer.Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.Alex Stamos has become Chief Information Security Officer at Cognition.More People On The MoveExpert Insights Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fgoogle-ai-is-changing-the-pace-and-profile-of-vulnerability-discovery\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F07\u002FAI-Chatbot-GenAI-artificial-intelligence.jpg","2026-09-30T14:05:58+00:00","2026-09-30T16:00:57.468427+00:00",8,[18,21,23,25,27,30],{"name":19,"type":20},"Privileged Remote Access","product",{"name":22,"type":20},"Remote Support",{"name":24,"type":20},"LiteLLM",{"name":26,"type":20},"Langflow",{"name":28,"type":29},"Google","vendor",{"name":31,"type":29},"BeyondTrust","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48,53],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":54},{"id":32,"icon":34,"name":35,"slug":36},[56],{"type":57,"value":58,"context":59},"cve","CVE-2026-1731","Unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, discovered by an AI research agent."]