Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
Mountain View desk3 min

Google Warns AI May Help Attackers Exploit Known Vulnerabilities Faster

Google Threat Intelligence Group says AI may make it easier to analyze patches and disclosures and exploit known flaws faster. Its data show rising observed exploitation, but do not prove AI caused the increase.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google Threat Intelligence Group (GTIG) says threat actors may be using large language models and other AI tools to analyze patches, product versions, vulnerability notices and proof-of-concept code faster—and potentially weaponize already disclosed vulnerabilities. That is a warning about a possible shift in attackers’ efficiency, not proof that AI caused the rise in exploitation GTIG measured. Its data show more observed exploited vulnerabilities in 2026, while zero-day exploitation rose more modestly.

What Google is warning about

In a post published September 30, 2026, GTIG says it is possible that threat actors are using LLMs and other AI tools to automate comparisons between software versions, patches, vulnerability announcements and proof-of-concept code. That could help them turn disclosed flaws into working attacks against organizations that have not yet applied a fix.

The distinction matters: this is a hypothesis about how attackers may be using AI, not a finding that AI has been proven to cause the increase in exploitation. GTIG’s report, credited to Robin Grunewald, Supriya Mazumdar and Kelli Vanderlee, covers vulnerability disclosures from January 1, 2025 through August 31, 2026. Read GTIG’s analysis, “Vulnerability Discovery and Exploitation Trends in the AI Era.”

What GTIG’s 2026 figures show

GTIG reports that both monthly vulnerability disclosures and its observed count of exploited vulnerabilities increased in 2026. The figures describe activity tracked by the group; they are not a count of every vulnerability or attempted attack worldwide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Measure 2025 2026 period reported
Monthly vulnerability disclosures not stated as a yearly average (GTIG) 5,045 in January and 10,740 in August (GTIG)
Observed exploited vulnerabilities Average of 10.5 per month (GTIG) Average of 18 per month, January–August (GTIG)
Observed zero-day exploitation Average of 8 per month (GTIG) Average of 11 per month, January–August; 22 in August (GTIG)

Zero-days are vulnerabilities exploited before a fix is publicly available. GTIG says they made up 62% of its observed exploited vulnerabilities during January–August 2026, even though zero-days were a small share of all disclosed vulnerabilities. That percentage applies to the exploited vulnerabilities GTIG observed in that period; it is not the share of all disclosed flaws that were attacked.

Why more CVEs do not automatically mean more danger

A higher disclosure count is not, by itself, evidence that every added entry is exploitable, severe or under attack. GTIG cautions that automated CVE Numbering Authority assignment policies can inflate raw totals. As an example, it cites roughly 5,000 CVEs whose descriptions included “Linux Kernel” from January through August 2026, with no observed in-the-wild zero-days in that group.

Rank #2
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

GTIG also distinguishes its own vulnerability risk ratings from CVSS severity scores. A disclosure total, a severity score and evidence of active exploitation answer different questions; none should be treated as a direct substitute for the others.

AI-assisted discovery and the race to patch

GTIG describes a possible collision between faster vulnerability discovery and faster exploitation. Its example is CVE-2026-1731, an unauthenticated OS command-injection flaw in BeyondTrust Privileged Remote Access and Remote Support. According to GTIG, third-party research agent Hacktron AI discovered the flaw autonomously. GTIG then observed a threat cluster exploiting it within four days of public disclosure, followed by five additional clusters within seven days.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

GTIG says the campaigns used the vulnerability for initial access and then involved actions including privilege escalation, data exfiltration and delivery of secondary payloads. This example shows why time to remediation matters, but it does not establish that AI was used by the attackers in those campaigns.

The group calls the higher-risk profile it sees in some AI-discovered vulnerabilities an early indicator, not an established trend. Its summary says AI-assisted discovery found proportionally fewer low-risk and more moderate-risk vulnerabilities, as well as more flaws leading to remote code execution. That does not mean every AI-discovered flaw is severe, or that AI alone explains those characteristics.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations should do

GTIG recommends moving away from unprioritized mass-patching toward threat-intelligence-driven triage, targeted edge defense and automated, agentic remediation. In practice, this means keeping patch management in place while directing the fastest response to vulnerabilities that combine credible exploitation evidence with exposure in the organization’s environment.

  • Prioritize evidence, not just volume. Use reports of active exploitation and relevant threat intelligence alongside severity ratings and asset exposure when deciding what to fix first.
  • Find exposed systems quickly. Identify internet-facing products and services that contain affected software, especially where a flaw could provide initial access.
  • Speed up safe remediation. Automate asset identification, patch deployment and verification where the organization can do so reliably; retain controls for testing and exceptions.
  • Keep patching broadly. Risk-based triage helps allocate urgency, but it is not a reason to ignore less-publicized vulnerabilities or leave a backlog unmanaged.

The practical concern is not that every new disclosure will become an AI-powered attack. It is that attackers may be able to extract useful exploit details from public information more quickly, making delays in identifying and fixing exposed systems more consequential.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
Network Security, Firewalls, and VPNs: . (Issa)
Network Security, Firewalls, and VPNs: . (Issa)
New Chapter on detailing network topologies; Increased coverage on device implantation and configuration
$57.99
SaleBestseller No. 3

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.