‘Threat actors may find it more accessible or efficient to use LLM and AI tools’: Google warns AI explosion will lead to more dangerous and advanced security threats
- AI is accelerating the exploitation of known vulnerabilities more than zero-day discovery
- Google saw sharp increases in disclosed flaws and real-world exploitation
- Defenders must prioritize intelligence-based patches as weapons use accelerates in n days
Artificial Intelligence (AI) is helping cybercriminals find and exploit software errors faster, easier and with greater consequences, according to a new report from the Google Threat Intelligence Group (GTIG). However, it is not as one would expect: very little attention is paid to zero-day vulnerabilities.
GTIG’s Vulnerability Discovery and Exploitation Trends in the Age of AI paper describes how AI is already having a “measurable impact” on the vulnerability landscape, not only in the speed at which new flaws are discovered, but also in the nature of the vulnerabilities themselves. Researchers found that the number of faults discovered in 2026 doubled throughout the year, and the number of faults exploited in the wild also increased significantly.
GTIG says the number of bugs found each month this year rose from 5,045 in January to 10,740 in August 2026. Over the same period, the average number of bugs exploited in the wild rose from 10.5 per month in 2025 to 18 per month.
Latest videos ofTechnologyRadar
Accelerate exploitation by n days
But it seems that AI’s ace in the hole is not finding zero days, as Mythos would have us think. Google researchers found only a marginal increase in zero-day exploitation (from 8 per month in 2025 to 11 per month this year). Instead, GTIG argues that the biggest threat is the rapid militarization of n-day faults:
“Threat actors may find it more accessible or efficient to use LLM and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and proof-of-concept (POC) code to quickly weaponize n-days, rather than discovering new zero-days,” the report states.
In other words, the exploit growth recorded this year occurred primarily within previously known vulnerabilities, not zero days. The number of high-risk flaws exploited doubled year over year, Google said.
Finding high impact faults
But AI is also helping defenders, especially when it comes to filtering out less impactful failures and focusing on the most dangerous ones. If we look only at vulnerabilities discovered with the help of AI, Google says there are proportionally fewer low-risk vulnerabilities and significantly more medium- and high-risk vulnerabilities. In fact, 50% of vulnerabilities discovered by AI resulted in remote code execution (RCE), compared to 26% across the broader vulnerability ecosystem.
GTIG says the security community is using AI primarily for high-level flaws in critical infrastructure, privilege boundaries, core libraries, and execution environments where they are most likely to be found.
Google highlighted at least one example where a vulnerability discovered by AI quickly attracted the attention of threat actors. The company cited CVE-2026-1731, a command injection vulnerability in BeyondTrust products that was discovered by a third-party AI research agent. GTIG said threat actors began exploiting the flaw within days of its public disclosure, using it in campaigns that included privilege escalation, data theft, and malware deployment.
In the near future, both vulnerability discovery and exploitation rates are expected to increase, Google says. Threat actors are increasingly experimenting with AI to create exploits, as well as various vulnerability discovery tools.
Advocates, on the other hand, must focus even more on n-days and understand that criminals will be able to weaponize them at unprecedented speed.
As a result, organizations will need to move away from broad, unprioritized patch programs and toward intelligence-driven vulnerability management that can keep pace with increasingly automated adversaries.
“GTIG expects vulnerability discovery and exploitation to continue to grow in the short and medium term,” Google said. “To counter the increased risk from rapid discovery and exploitation of vulnerabilities, organizations must move from mass unprioritized patching to threat intelligence-based triage, combining targeted edge defense with automated and agent remediation.”
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.



Post Comment