LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
vulnerability

Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

Google's Threat Intelligence Group (GTIG) has reported a significant surge in vulnerability disclosures, with monthly totals more than doubling from January to August of this year. The number of disclosures climbed from 5,045 in January to over 10,000 in both July and August, peaking at 10,740 last month. This increase is attributed by GTIG researchers to the growing influence of artificial…

ZeroDay News ·

Source: The Record

Google's Threat Intelligence Group (GTIG) has reported a significant surge in vulnerability disclosures, with monthly totals more than doubling from January to August of this year. The number of disclosures climbed from 5,045 in January to over 10,000 in both July and August, peaking at 10,740 last month. This increase is attributed by GTIG researchers to the growing influence of artificial intelligence in both vulnerability discovery and exploitation.

Beyond the sheer volume of disclosures, GTIG noted that the number of distinct vulnerabilities exploited in the first eight months of 2026 has already surpassed the total for all of 2025. There have been 141 exploited vulnerabilities this year, compared to 127 last year. The group emphasized that this rise in exploitation is primarily driven by the rapid, targeted weaponization of known, high-risk vulnerabilities (n-days) rather than a proliferation of zero-day exploits.

Researchers suggest that threat actors are leveraging large language models (LLMs) and other AI tools to automate the analysis of differences between product versions, patches, public vulnerability disclosures, and proof-of-concept (POC) code. This allows them to quickly weaponize n-days, making it a more accessible and efficient approach than discovering new zero-days.

As an illustration, Google highlighted CVE-2026-1731, a vulnerability in BeyondTrust software that federal cyber defenders flagged in February. This flaw was autonomously discovered by a third-party research agent named Hacktron AI. Following its public disclosure, GTIG observed multiple threat clusters exploiting this vulnerability in targeted initial-access campaigns to bypass enterprise perimeters. Within four days of disclosure, one threat cluster was observed exploiting it, followed by five more within seven days. These actors engaged in post-exploitation activities such as privilege escalation, data exfiltration, and deploying secondary payloads like SNOWLIGHT, SPARKRAT, and cryptominers. This case demonstrates the formidable capacity of autonomous research agents to uncover high-severity flaws when directed at critical attack surfaces.

AI agents are predominantly being used to find medium and high-risk vulnerabilities. GTIG classifies a bug as high-risk if its exploitation would have a notable, direct impact on the security of targeted devices and networks without requiring significant mitigating factors, and if exploitation is expected to be highly reliable and scalable.

Many of the disclosures this year have originated from a limited number of vendors, including router firmware company Totolink and Oracle. Threat actors continue to concentrate their exploitation efforts on perimeter appliances and exposed enterprise services; 14% of vulnerabilities exploited between January and August affected edge and security appliances.

These findings align with recent reports from the Cybersecurity and Infrastructure Security Agency (CISA), which indicated that over 67,000 new CVEs have been published in 2026, with projections for a total of 96,000 by year-end. The National Institute of Standards and Technology’s National Vulnerability Database program also reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 being one-third higher than the same period in 2025. GTIG anticipates that AI-assisted vulnerability discovery and exploitation will continue to grow in the short to medium term.

vulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

vulnerability

AI slop submissions force Google to freeze its open-source bug bounty

Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers…

breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.

ai

Apple tightens macOS disk access as AI agents become more powerful

Apple is implementing stricter controls for Full Disk Access in macOS, citing an increased risk to user privacy from increasingly capable and autonomous AI agents. The company indicated that future macOS versions will require users to take explicit steps to grant applications this permission. A specific rollout date and the precise mechanics of these new controls have not yet been detailed.

nation-state

doxx.net opens Agentic Defined Networking public beta, raises $38 million

doxx.net has launched the public beta of its Agentic Defined Networking (ADN) platform, which enables users and their AI agents to establish private, secure networks and communicate without intermediary servers. The company also announced it has secured $38 million in Series A funding, led by Andreessen Horowitz, with additional participation from Animo Ventures and Focal.vc. As part of the…

nation-state

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

David Robinson, a veteran safety expert at OpenAI, has resigned from the company, citing concerns about its culture and rapid AI development model. Robinson, who was instrumental in authoring safety reports accompanying major product launches during his three-and-a-half-year tenure, stated that he believes the company's current trajectory is unacceptable.