Cybersecurity Research

AI Is Supercharging Vulnerability Discovery, and Attackers Are Keeping Pace

Key Takeaway Small businesses should prioritise patching based on actual exploitation risk rather than trying to fix every vulnerability at once, and ensure internet-facing systems are updated promptly.

New research from Google Threat Intelligence Group (GTIG) shows that artificial intelligence is reshaping how security vulnerabilities are found and exploited. Monthly vulnerability disclosures doubled between January and August 2026, rising from 5,045 to 10,740. Over the same period, the number of vulnerabilities actively exploited by attackers nearly doubled too, climbing from an average of 10.5 per month in 2025 to 18 per month in 2026. Zero-day exploitation, attacks on flaws with no available patch, also rose, from an average of 8 to 11 incidents per month.

Just as concerning, GTIG found that AI-assisted discovery is not only producing more vulnerabilities, but more serious ones. Compared with earlier methods, AI-driven research is turning up proportionally fewer low-risk issues and more moderate-risk vulnerabilities, including a greater share that could allow attackers to remotely take control of systems.

GTIG expects this trend to continue growing in the near term. The researchers argue that organisations need to move away from patching everything as it appears, and instead prioritise fixes based on real threat intelligence, combined with strong defences at network edges and faster, more automated remediation processes.

Primary source nvd.nist.gov -> cisa.gov ->
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Google Threat Intelligence. We link back to every original so you can read it yourself.