Security News

AI Is Supercharging How Fast Hackers Exploit Software Bugs, Google Warns

The Record · 1 Oct 2026
Key Takeaway Apply security patches as soon as they're released rather than waiting, since attackers are now using AI to exploit known vulnerabilities within days of disclosure.

Google's Threat Intelligence Group says vulnerability disclosures have surged in 2026, rising from 5,045 in January to a peak of 10,740 in August. The number of distinct vulnerabilities disclosed and exploited in the first eight months of the year has already surpassed totals for all of 2025, with 141 exploited flaws recorded so far compared to 127 last year.

Rather than a wave of brand new zero-day discoveries, researchers say the increase is driven by attackers rapidly weaponising already-patched vulnerabilities (known as n-days) using AI tools. Hackers appear to be using large language models to compare software versions, analyse patches, and study proof-of-concept code, allowing them to build working exploits much faster than before. One example cited is a BeyondTrust vulnerability that was exploited by multiple attacker groups within just days of being publicly disclosed.

Google expects this AI-assisted approach to exploitation to keep growing in the near term, meaning the window between a patch being released and attackers exploiting it is shrinking fast.

Primary source cisa.gov -> cisa.gov ->

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.