Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

A surge in vulnerability disclosures, driven by AI-powered tools, has significantly altered the landscape of cybersecurity threats. According to Google’s Threat Intelligence Group (GTIG), the number of vulnerabilities disclosed each month has more than doubled this year, with a corresponding increase in exploitation rates.

The GTIG report analyzed data from January 2025 through August 2026 and found that monthly disclosures rose dramatically, peaking at 10,740 in August. This surge is attributed to the growing use of AI-powered tools by researchers and threat actors alike. These tools can quickly scan vast amounts of code and identify vulnerabilities, making it easier for attackers to find and exploit weaknesses.

One concern raised by GTIG is that high-risk disclosures have grown significantly, with a 167% increase from January to August. This means that more vulnerabilities are being discovered that could potentially lead to serious security breaches. Furthermore, the report notes that zero-day exploitation has increased only marginally, but the number of non-zero-day (n-days) exploits has skyrocketed.

GTIG suggests that threat actors may be using AI tools to automate analysis and rapidly weaponize n-days, rather than discovering new zero-days. This would explain why we’re seeing a surge in exploitation rates without a corresponding increase in zero-day attacks. The report also highlights the importance of distinguishing between vulnerabilities discovered by human researchers and those found by AI-powered tools.

Interestingly, GTIG found that vulnerabilities likely discovered by AI have a different risk profile compared to non-AI vulnerabilities. For instance, 39% of AI-discovered vulnerabilities were rated low-risk, while only 26% of non-AI vulnerabilities had this rating. This may be because research programs are deploying AI agents to focus on high-impact findings.

The report also notes that some AI-discovered vulnerabilities have been exploited in the wild. For example, CVE-2026-1731, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, was discovered autonomously by the Hacktron AI research agent and later exploited within four days of public disclosure.

In addition to these findings, GTIG tracked 2,076 AI-related CVEs between January 2025 and August 2026. While only a handful of these have been confirmed as exploited in the wild, this trend highlights the growing importance of securing AI systems themselves.

As the report concludes, “GTIG expects that rates of vulnerability discovery and exploitation are likely to continue to increase in the short to medium term.” This emphasizes the need for organizations to stay vigilant and adapt their security strategies to address these evolving threats.

For individuals and organizations, this means keeping pace with the rapidly changing threat landscape. One key takeaway is to prioritize patching and updates, especially for AI-related systems. It’s also essential to implement robust vulnerability management processes that can quickly identify and remediate emerging threats. By staying proactive and informed about the latest developments in AI-powered attacks, we can better defend against these evolving threats.


Source: SecurityWeek — 2026-09-30