LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
vulnerability

The vulnerabilities AI finds are the ones attackers want

Threat actors are rapidly exploiting vulnerabilities discovered by artificial intelligence research agents, often within days of public disclosure, according to new research from Google Threat Intelligence Group (GTIG). The group's analysis, covering January 2025 to August 2026, indicates a significant increase in overall vulnerability exploitation, particularly for "n-day" flaws.

ZeroDay News ·

Source: Help Net Security

Threat actors are rapidly exploiting vulnerabilities discovered by artificial intelligence research agents, often within days of public disclosure, according to new research from Google Threat Intelligence Group (GTIG). The group's analysis, covering January 2025 to August 2026, indicates a significant increase in overall vulnerability exploitation, particularly for "n-day" flaws.

Monthly CVE disclosures more than doubled in 2026, from 5,045 in January to 10,740 in August. While only a small fraction of these are observed exploited in the wild (0.23% or about one in 431), the total number of exploited vulnerabilities rose from 127 in all of 2025 to 141 in the first eight months of 2026. Zero-day exploitation also increased, from an average of 8 per month in 2025 to 11 per month in 2026. GTIG suggests that the majority of this growth in exploitation stems from n-day vulnerabilities, possibly due to threat actors leveraging large language models and AI tools to quickly analyze patches, disclosure announcements, and proof-of-concept code for weaponization.

Vulnerabilities identified as likely discovered by AI agents are often more severe. Half of these AI-found flaws lead to remote code execution, compared to 26% of vulnerabilities discovered through other means. AI-discovered vulnerabilities are also less frequently rated as low risk, with 39% being low risk and 58% medium risk, whereas vulnerabilities found by other methods were 69% low risk and 28% medium risk. This trend likely reflects how research programs scope and deploy AI systems, often tasking them with auditing critical infrastructure and sensitive privilege boundaries.

GTIG noted that public data likely undercounts AI-discovered vulnerabilities because CVE records lack a standard tag for AI attribution, and cloud and SaaS providers often fix AI-found flaws in production without requesting CVE IDs.

A notable example of rapid exploitation involved CVE-2026-1731, an unauthenticated OS command injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support. This flaw, discovered by the Hacktron AI research agent, was exploited by one threat cluster within four days of its public disclosure, and by five additional clusters within seven days. Attackers used it in targeted initial-access campaigns to escalate privileges, exfiltrate data, and deploy payloads such as SNOWLIGHT, SPARKRAT, and cryptominers.

The research also highlighted a growing number of vulnerabilities in AI-related software itself. Between January 2025 and August 2026, GTIG tracked 2,076 such vulnerabilities, with over 1,500 disclosed in 2026 alone. Half of this year's disclosures affect AI agent orchestration frameworks like Flowise and Langflow, where attackers exploit code execution nodes via prompt injection or crafted workflow JSONs.

Inference and serving software, including vLLM, Ollama, and LiteLLM, saw 212 vulnerabilities disclosed in 2026. Nearly a quarter of these vulnerabilities originate from unauthenticated API endpoints or server-side request forgery, which can enable attackers to bypass perimeter firewalls, consume GPU resources, or extract model checkpoints. Compromised enterprise AI gateways risk exposing third-party API keys and private prompt streams containing personally identifiable information or proprietary source code.

While only a handful of AI-related vulnerabilities have been confirmed as exploited in the wild, these include a command injection flaw in LiteLLM (CVE-2026-42271) leading to host takeover and API credential theft, and two Langflow flaws (CVE-2026-5027 and CVE-2025-3248) that permit file writing to the host or remote code execution.

GTIG anticipates that both vulnerability discovery and exploitation will continue to rise in the short to medium term. To mitigate this increased risk, organizations are advised to shift from unprioritized mass-patching to threat-intelligence-driven triage, combining targeted edge defense with automated, agentic remediation.

vulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

vulnerability

AI slop submissions force Google to freeze its open-source bug bounty

Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers…

breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.

ai

Apple tightens macOS disk access as AI agents become more powerful

Apple is implementing stricter controls for Full Disk Access in macOS, citing an increased risk to user privacy from increasingly capable and autonomous AI agents. The company indicated that future macOS versions will require users to take explicit steps to grant applications this permission. A specific rollout date and the precise mechanics of these new controls have not yet been detailed.

nation-state

doxx.net opens Agentic Defined Networking public beta, raises $38 million

doxx.net has launched the public beta of its Agentic Defined Networking (ADN) platform, which enables users and their AI agents to establish private, secure networks and communicate without intermediary servers. The company also announced it has secured $38 million in Series A funding, led by Andreessen Horowitz, with additional participation from Animo Ventures and Focal.vc. As part of the…

nation-state

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

David Robinson, a veteran safety expert at OpenAI, has resigned from the company, citing concerns about its culture and rapid AI development model. Robinson, who was instrumental in authoring safety reports accompanying major product launches during his three-and-a-half-year tenure, stated that he believes the company's current trajectory is unacceptable.