In short: Google's Threat Intelligence Group (GTIG) published a report showing publicly disclosed vulnerabilities doubled in 2026 — from 5,045 in January to 10,740 in August — while the share of bugs actually exploited in the wild grew almost as fast. The driver is AI: attackers now use LLMs to automatically diff software versions, parse patches and disclosure bulletins, and weaponize a fresh vulnerability within days instead of weeks. One AI-discovered flaw was already under active exploitation just 4 days after public disclosure. That shrinks the window ordinary users have to patch before attackers find them — which is exactly why keeping security updates current matters more than ever.
What Google's report actually found
GTIG researchers analyzed vulnerability disclosure data from January 2025 through August 2026 and found a sharp inflection point. Monthly disclosures rose from 5,045 in January 2026 to 10,477 in July, peaking at 10,740 in August. In parallel, the average monthly count of vulnerabilities actually exploited in the wild — not just theoretically disclosed — nearly doubled too. Google's conclusion: the surge isn't driven by a sudden flood of brand-new zero-days, but by the fast, targeted weaponization of already-known, high-risk bugs. Speed, not volume, is the new threat.
How AI is changing the mechanics of an attack
The report's key finding is that vulnerabilities discovered by AI itself are statistically far more dangerous than the rest: roughly half of them enable remote code execution (RCE), compared to just 26% among vulnerabilities disclosed through traditional means. Attackers are increasingly using LLMs to automate diffing of pre- and post-patch software versions, parse official advisories, and analyze published proof-of-concept code — work that used to take a skilled analyst hours and now takes minutes.
Case study: from AI discovery to mass exploitation in 4 days
The report walks through a concrete example: CVE-2026-1731, an unauthenticated command-injection flaw in BeyondTrust Privileged Remote Access and Remote Support. It was discovered autonomously by a third-party AI research agent, Hacktron AI. Just 4 days after public disclosure, GTIG observed the first threat cluster exploiting it — and five more independent clusters joined within a week. Post-exploitation activity included privilege escalation, data exfiltration, and dropping secondary payloads such as cryptominers and the SNOWLIGHT and SPARKRAT remote-access tools.
Who's behind the AI-powered vulnerability hunting
Google directly links the surge in AI-driven vulnerability research to threat actors researchers associate with China and North Korea. Earlier in 2026, the company had already documented the first known case of a suspected DPRK-linked group using an AI model to automate CVE analysis and PoC verification, firing thousands of near-identical queries at the model — a volume of research that would be nearly impossible to sustain manually without an LLM.
What this means for ordinary users
For individuals, these attacks typically don't target a home PC directly — they aim at corporate and government infrastructure: remote-access gateways, VPN appliances, corporate portals. But breaches of exactly that kind of infrastructure are the most common source of the next wave of personal-data leaks: attackers compromise a corporate system and walk away with a customer database that later gets sold or leaked. A shrinking gap between disclosure and mass exploitation means putting off an update "until later" is measurably riskier than it was a year ago.
How to protect yourself if you're not a corporate security team
- Turn on automatic updates on every device and your router — most mass-exploitation campaigns abuse already-patched flaws that simply weren't installed, not unknown vulnerabilities.
- Don't postpone app and OS updates for a "convenient moment." A week or two used to be a safe buffer; now a patch can be weaponized in 4 days.
- Enable two-factor authentication on services that hold your personal data — it limits the damage even if the service itself is breached through a vendor-side vulnerability.
- Encrypt your traffic on any network you don't fully trust. A VPN won't close a vulnerability on someone else's server, but it does protect your own connection from interception while you log into a bank or email over public Wi-Fi. LiMP VPN is a no-logs service for Android, Windows and Chrome with modern encryption protocols.
FAQ
Quick answers to the questions this kind of AI-accelerated exploitation story usually raises.
Sources
- Google Cloud Blog (GTIG) — "Vulnerability Discovery and Exploitation Trends in the AI Era," October 2026
- Help Net Security — "The vulnerabilities AI finds are the ones attackers want," October 1, 2026
- SecurityLab.ru — "AI is changing vulnerability discovery: half of found bugs lead to code execution," October 2026
