Back to News
RSS feedtherecord.media

Google Reports AI-Driven Surge in Vulnerability Exploitation

Summary

Google’s Threat Intelligence Group (GTIG) says vulnerability disclosures rose from 5,045 in January to a record 10,740 in August 2026, with monthly totals exceeding 10,000 in both July and August. The number of vulnerabilities exploited during the first eight months, 141, already surpassed the 127 exploited in all of 2025. GTIG attributes the increase primarily to the targeted weaponization of high-risk, already disclosed vulnerabilities rather than a wave of new zero-days. According to the researchers, threat actors are using large language models and other AI tools to compare product versions, patches, disclosure notices, and proof-of-concept code, making n-day exploitation faster and more accessible. Google expects AI-assisted discovery and exploitation to continue growing in the short to medium term. The report highlights CVE-2026-1731 in BeyondTrust software, which was autonomously found by the third-party research agent Hacktron AI. GTIG observed one threat cluster exploiting the flaw within four days of disclosure and five more within seven days; the observed activity included privilege escalation, data exfiltration, and delivery of SNOWLIGHT, SPARKRAT, and cryptominers. AI agents are being used mainly against medium- and high-risk vulnerabilities, while attackers continue to target perimeter appliances and exposed enterprise services. Fourteen percent of vulnerabilities exploited from January through August affected edge and security appliances. The findings accompany wider growth in CVE reporting, with more than 67,000 new CVEs published in 2026 and projections of 96,000 by year-end, according to figures cited from CISA and NIST.