AI News Feed
Market watch
Cybersecurity

Google Report Finds Monthly Vulnerability Disclosures Doubled as AI Reshapes Which Flaws Are Found

Google's Threat Intelligence Group reports monthly software vulnerability disclosures doubled between January and August, to 10,740, with AI agents surfacing a rising share of flaws, including 58% rated moderate risk.

GTIG cautioned that raw totals can overstate the threat, because automated identifier assignment in open-source ecosystems inflates them. Flaws with "Linux Kernel" in their descriptions accounted for about 5,000 records this year without producing a single zero-day exploited in the wild, according to the report. High-risk disclosures on GTIG's own scale rose 167 percent over the same months to 350 in August, and 128 of those came from Oracle's quarterly patch release and Linux kernel network driver advisories.

By GTIG's count, attackers exploited 141 newly disclosed vulnerabilities in the wild between January and August, more than the 127 recorded across all of 2025. Measured against disclosure volume, that is about one flaw in 431, and the report notes that a single vendor's disclosure cycle or one busy campaign can move the monthly figure. Zero-day exploitation has averaged 11 a month this year against eight in 2025, with most months landing between eight and 12 until August brought 22. Zero-days, meaning new vulnerabilities that have not been patched, still made up 62 percent of the 141 exploited flaws. Most of the growth, GTIG suggests, has come from n-days, flaws attackers pursue once they are public and usually already patched.

The report says attackers may be using large language models to compare product versions and patches so they can turn known flaws into working exploits quickly. Exploited high-risk flaws numbered 75 this year, up from 28 in all of 2025.

GTIG believes public data undercounts the vulnerabilities AI itself is finding, since vulnerability databases carry no standard tag for AI-assisted discovery. Large cloud and software-as-a-service providers also fix many AI-surfaced bugs in production without requesting an identifier, because those identifiers are normally reserved for software that customers have to patch themselves.

Among the vulnerabilities GTIG identified as likely AI discoveries, 58 percent fell in the moderate tier of its risk scale. Bugs found by people and conventional scanners land there about half as often, and 69 percent of those rate as low-risk. Researchers tend to aim their agents at critical infrastructure and sensitive privilege boundaries on purpose, and GTIG thinks that choice likely explains much of the gap.

Remote code execution shows up in only 26 percent of all other disclosures. The report says AI's higher rate likely stems from how well agents pick out memory corruption and logic bypasses deep in C and C++ code that static analyzers tend to miss.

GTIG treats confirmed attacks on AI-found flaws as an early indicator for now. The example it cites to show the risk is "not purely theoretical" is CVE-2026-1731, a bug that lets an unauthenticated attacker inject operating system commands into BeyondTrust's Privileged Remote Access and Remote Support products and that a research agent from Hacktron AI found autonomously. Within four days of disclosure in February, GTIG saw one threat cluster exploiting the flaw, and five more had joined within a week. The attackers escalated privileges and stole data, and payloads they dropped included SNOWLIGHT and SPARKRAT malware plus cryptocurrency miners.

The report's final section covers flaws in AI software. Of the 2,076 such disclosures GTIG has tracked since the start of 2025, more than 1,500 came this year, with agent orchestration frameworks such as Flowise and Langflow accounting for roughly half. Visual workflow builders of that kind often include nodes that execute code, and attackers can reach them through prompt injection or a crafted workflow file. Inference and serving software including vLLM, Ollama and LiteLLM drew 212 disclosures, and GTIG traced nearly a quarter of them to unauthenticated application programming interface endpoints or server-side request forgery.

GTIG has not yet observed zero-day exploitation of AI infrastructure. Only a handful of disclosed flaws have been exploited in the wild, among them a command injection bug in LiteLLM's Model Context Protocol server preview endpoints and two in Langflow. In July, Sysdig documented an autonomous ransomware attack that broke in through the older of the Langflow flaws. The Google unit expects discovery and exploitation to keep climbing over the short to medium term, with exploitation remaining concentrated on perimeter appliances and exposed enterprise services.