INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Google's AI fuels vulnerability disclosures doubling to 10,000 monthly

| 2026-09-30 14:05 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A significant increase in vulnerability disclosures and exploitation was reported by Google's Threat Intelligence Group (GTIG) on September 30, 2026. The number of vulnerabilities disclosed doubled between January and August, reaching a peak of 10,740 last month, with total disclosures starting at 5,045 in January. This surge is attributed to the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-days. GTIG observed threat actors using AI-assisted vulnerability discovery and exploitation, conducting post-exploitation activities such as privilege escalation, data exfiltration, and dropping secondary payloads including SNOWLIGHT, SPARKRAT, and cryptominers. As of September 30, there have been at least 141 exploited vulnerabilities this year after 127 last year.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-1731 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-1731CVE-2026-1731
Target & Sectors
Global Scope
Incident Timeline
‎January 2025
Monthly vulnerability disclosures on Google's systems increased from 5,045 in January 2025 to a peak of 10,740 in August 2026.
‎between January 2025
Threat actors used AI to discover and report more than 1,500 vulnerabilities affecting AI orchestration frameworks between January 2025 and August 2026.
general_metric 1,500 August
‎2025/09/30
Threat actors have increased the rate of vulnerability discovery by 71.4% this year, with an average of 18 new vulnerabilities per month compared to 10.5 last year.
general_metric 141 distinct exploited vulnerabilities
general_metric 127 last year
‎January 2026
Threat actors used large language models and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept code.
infrastructure Linux
organisation Hacktron
organisation CVE
organisation CVSS
organisation POC
‎August 2026
Threat actors used AI to discover and disclose more than 1,500 vulnerabilities in AI orchestration frameworks between January 2025 and August 2026.
general_metric 1,500 August
‎2026/08/31
Google's Threat Intelligence Group reported that vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 on August 31, 2026.
attribution Google’s Threat Intelligence Group
‎2026/09/23
Threat actors published more than 67,000 new CVEs in 2026.
‎between 2020 and 2025
The National Institute of Standards and Technology's National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025.
industry Technology
attribution CISA
general_metric 263 %
‎2026/09/30
Threat actors are rapidly weaponizing high-risk exploits in the wild using AI tools and LLMs to automate analysis of vulnerabilities, rather than discovering new zero-days.
organisation Google
organisation CVE-2026
organisation BeyondTrust
organisation POC
organisation SPARKRAT
organisation GTIG
‎the first eight months of 2026
Threat actors exploited 141 distinct vulnerabilities in the first eight months of 2026, more than double the number seen in all of 2025.
general_metric 141 distinct exploited vulnerabilities
‎the first three months of 2026
CISA reported a 263% increase in annual CVE submissions between 2020 and 2025, with the first three months of 2026 seeing one-third more submissions than during the same period in 2025.
industry Technology
attribution CISA
general_metric 263 %
Tactical Metrics
Metrics
infrastructure
‎Linux
Affected Product