AI Is Supercharging How Fast Hackers Exploit Software Bugs, Google Warns
Google's Threat Intelligence Group says vulnerability disclosures have surged in 2026, rising from 5,045 in January to a peak of 10,740 in August. The number of distinct vulnerabilities disclosed and exploited in the first eight months of the year has already surpassed totals for all of 2025, with 141 exploited flaws recorded so far compared to 127 last year.
Rather than a wave of brand new zero-day discoveries, researchers say the increase is driven by attackers rapidly weaponising already-patched vulnerabilities (known as n-days) using AI tools. Hackers appear to be using large language models to compare software versions, analyse patches, and study proof-of-concept code, allowing them to build working exploits much faster than before. One example cited is a BeyondTrust vulnerability that was exploited by multiple attacker groups within just days of being publicly disclosed.
Google expects this AI-assisted approach to exploitation to keep growing in the near term, meaning the window between a patch being released and attackers exploiting it is shrinking fast.