'It is possible that threat actors are finding it more accessible or
efficient to use LLMs and AI tools': Google warns that AI explosion will lead to more dangerous and advanced security threats
Date:
Thu, 01 Oct 2026 13:15:00 +0000
Description:
It's not about zero-days, at all, but rather about properly exploiting
already known flaws, Google says.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter AI is accelerating exploitation of known vulnerabilities more than zero-day discovery Google observed sharp rises in disclosed flaws and real-world exploitation Defenders must
prioritize intelligence-led patching as n-day weaponization speeds up Artificial Intelligence (AI) is helping cybercriminals find and exploit software bugs faster, more easily, and with greater consequences, a new
report from the Google Threat Intelligence Group (GTIG) has claimed. However, its not in the way youd expect - theres very little focus on zero-day vulnerabilities.
GTIG's Vulnerability Discovery and Exploitation Trends in the AI Era paper outlines how AI is already having a measurable impact on the vulnerability landscape, not just in the speed at which new flaws are discovered, but also in the nature of the vulnerabilities themselves. Researchers found that the number of flaws discovered in 2026 doubled throughout the year, and the
number of those exploited in the wild rose significantly, as well. GTIG says that the number of bugs found each month this year rose from 5,045 in January to 10,740 in August 2026. During the same period, the average number of flaws exploited in the wild rose from 10.5 a month in 2025, to 18 a month. Latest Videos From TechRadar Watch full video here: Speeding up n-day exploitation But it seems AIs ace in the sleeve is not finding zero-days, as Mythos would have you think. Googles researchers found only a marginal increase in
zero-day exploitation (from 8 a month in 2025, to 11 a month this year). Instead, GTIG argues that the bigger threat is the rapid weaponization of n-day flaws:
"It is possible that threat actors are finding it more accessible or
efficient to use LLMs and AI tools to automate analysis of differences
between product versions, patches, vulnerability disclosure announcements,
and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days," the report states. You may like Companies need to focus on fixing exploitable vulnerabilities, not discovering as many as possible Why AI is accelerating old cyber risks, not creating new ones AI is changing security testing, but not all vulnerabilities are created equal
In other words, the exploitation growth recorded this year was mostly within previously known vulnerabilities, not zero-days. The number of exploited high-risk flaws doubled year-on-year, Google said. Finding high-impact flaws But AI is also helping defenders, especially when it comes to filtering out less impactful flaws and focusing on the most dangerous ones. Looking just at vulnerabilities discovered with the help of AI, Google says there are proportionally fewer low-risk ones, and significantly more medium and high-risk ones. In fact, 50% of AI-discovered vulnerabilities resulted in remote code execution (RCE), compared to 26% across the broader vulnerability ecosystem. Are you a pro? Subscribe to our newsletter Sign up to the
TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
or sponsors By submitting your information you agree to the Terms &
Conditions and Privacy Policy and are aged 16 or over.
GTIG says the security community is using AI primarily for high-level flaws
in critical infrastructure, privilege boundaries, core libraries, and runtime environments where theyre more likely to be found.
Google highlighted at least one example where an AI-discovered vulnerability quickly attracted the attention of threat actors. The company cited CVE-2026-1731, a command-injection vulnerability in BeyondTrust products that was discovered by a third-party AI research agent. GTIG said threat actors began exploiting the flaw within days of public disclosure, using it in campaigns that included privilege escalation, data theft, and malware deployment.
In the near future, both vulnerability discovery and exploitation rates are expected to grow, Google says. Threat actors are increasingly experimenting with AI to build exploits, as well as various vulnerability discovery tools. What to read next AI floods security teams with findings. The advantage is in what happens next Agentic AI is increasing the pressure on organizations to reduce cyber risk exposure Many companies deploying AI often end up with much bigger security issues, report warns
The defenders, on the other hand, need to focus on n-days even more, and understand that crooks will be able to weaponize them at unprecedented speed.
As a result, organizations will need to move away from broad, unprioritized patching programs and toward intelligence-driven vulnerability management capable of keeping pace with increasingly automated adversaries.
GTIG expects that vulnerability discovery and exploitation will continue to grow in the short to medium term, Google said. To counter the increased risk from rapid vulnerability discovery and exploitation, organizations must transition from unprioritized mass-patching to threat-intelligence-driven triage, combining targeted edge-defense with automated, agentic remediation. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/it-is-possible-that-threat-actors-are-f inding-it-more-accessible-or-efficient-to-use-llms-and-ai-tools-google-warns-t hat-ai-explosion-will-lead-to-more-dangerous-and-advanced-security-threats
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)