proomt

Search

Search posts, papers, and topics

All posts

Google Cloud BlogGoogle Threat Intelligence Group14 min readintermediate

Vulnerability Discovery and Exploitation Trends in the AI Era

Summary

Google Threat Intelligence found that AI is significantly changing the vulnerability landscape. In 2026, vulnerability disclosures and exploitation nearly doubled, with AI-assisted discovery finding more moderate-risk and RCE vulnerabilities, shifting focus from mass-patching to threat-intelligence-driven triage.

  • Vulnerability disclosures doubled in 2026, reaching over 10,000 per month by August.
  • In-the-wild exploitation increased from 10.5/month in 2025 to 18/month in 2026.
  • Zero-day exploitation increased marginally, but n-day exploitation grew significantly, suggesting rapid weaponization of disclosed flaws.
  • AI-assisted discovery found proportionally more Moderate-Risk and Remote Code Execution (RCE) vulnerabilities.

Security professionals and developers should care as the increased pace and changing risk profile of vulnerabilities demand a shift from mass-patching to targeted, intelligence-driven security strategies.

7/10

Related reading

  1. Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses

    Google’s Threat Intelligence team outlines three AI‑driven shifts—software build changes, expanded attack surface, and enhanced threat capabilities—then describes their multi‑model, graph‑based defense stack (AI Threat Tracker, in‑editor “spellcheck”, Wiz Security Graph, Gemini‑powered AI Threat Defense) and concrete threat examples like supply‑chain poisoning, LLMJacking, and AI‑orchestrated cre…

    Google Cloud Bloggoogle.com11 min
  2. AI Agents Are Disrupting Open Source Security Disclosure

    AI agents can turn minimal public hints about software bugs into working exploits, rendering traditional embargoes ineffective. The article cites a study where a GPT‑4 agent exploited 87% of a 15‑vulnerability benchmark from CVE descriptions and discusses faster releases and revocable capabilities as mitigations.

    InfoQinfoq.com2 min
  3. Changing the game: How Google uses agentic AI to secure hundreds of millions of lines of code

    Google’s AI & Infrastructure team built an agentic pipeline (Mantis) that runs pre‑submit AI‑driven scans on every code check‑in, validates findings with a fast triage agent (AST + call‑graph analysis) achieving >92% precision in <1 min, then auto‑generates fixes via a bug‑fix agent. Localized threat models and a two‑step scan cut false‑positives to ~3% and prevent hundreds of vulnerabilities eac…

    Google Cloud Bloggoogle.com4 min