INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Google's AI fuels vulnerability disclosures doubling to 10,000 monthly
| 2026-09-30 14:05 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
A significant increase in vulnerability disclosures and exploitation was reported by Google's Threat Intelligence Group (GTIG) on September 30, 2026. The number of vulnerabilities disclosed doubled between January and August, reaching a peak of 10,740 last month, with total disclosures starting at 5,045 in January. This surge is attributed to the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-days. GTIG observed threat actors using AI-assisted vulnerability discovery and exploitation, conducting post-exploitation activities such as privilege escalation, data exfiltration, and dropping secondary payloads including SNOWLIGHT, SPARKRAT, and cryptominers. As of September 30, there have been at least 141 exploited vulnerabilities this year after 127 last year.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2026-1731 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-1731CVE-2026-1731
Target & Sectors
Global Scope
Incident Timeline
January 2025
Monthly vulnerability disclosures on Google's systems increased from 5,045 in January 2025 to a peak of 10,740 in August 2026.
between January 2025
Threat actors used AI to discover and report more than 1,500 vulnerabilities affecting AI orchestration frameworks between January 2025 and August 2026.
Click on any entity below to view its context and source!
general_metric
1,500 August
GTIG tracked 2,076 AI-related CVEs between January 2025 and August 2026, including more than 1,500 this year, roughly half of which affect AI orchestration frameworks.
2025/09/30
Threat actors have increased the rate of vulnerability discovery by 71.4% this year, with an average of 18 new vulnerabilities per month compared to 10.5 last year.
Click on any entity below to view its context and source!
January 2026
Threat actors used large language models and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept code.
Click on any entity below to view its context and source!
infrastructure
Linux
Vulnerabilities whose description mentions the Linux kernel alone generated roughly 5,000 CVEs between January and August, with no in-the-wild zero-day exploitation observed.
organisation
Hacktron
One example is
CVE-2026-1731
, an unauthenticated OS command injection flaw in BeyondTrust Privileged Remote Access and Remote Support, discovered autonomously by the Hacktron AI research agent.
organisation
CVE
The researchers caution that raw volume can be misleading, as automated CVE assignment in open source ecosystems can inflate the numbers.
organisation
CVSS
High-risk disclosures, based on GTIG’s own ratings rather than CVSS, grew 167%, from 131 in January to 350 in August.
organisation
POC
“It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days,” the report reads.
August 2026
Threat actors used AI to discover and disclose more than 1,500 vulnerabilities in AI orchestration frameworks between January 2025 and August 2026.
Click on any entity below to view its context and source!
general_metric
1,500 August
GTIG tracked 2,076 AI-related CVEs between January 2025 and August 2026, including more than 1,500 this year, roughly half of which affect AI orchestration frameworks.
2026/08/31
Google's Threat Intelligence Group reported that vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 on August 31, 2026.
Click on any entity below to view its context and source!
attribution
Google’s Threat Intelligence Group
Vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 last month, Google’s Threat Intelligence Group (GTIG) said Wednesday.
2026/09/23
Threat actors published more than 67,000 new CVEs in 2026.
between 2020 and 2025
The National Institute of Standards and Technology's National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025.
Click on any entity below to view its context and source!
industry
Technology
The National Institute of Standards and Technology’s National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 one-third higher than during the same period in 2025, CISA said.
attribution
CISA
The National Institute of Standards and Technology’s National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 one-third higher than during the same period in 2025, CISA said.
general_metric
263 %
The National Institute of Standards and Technology’s National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 one-third higher than during the same period in 2025, CISA said.
2026/09/30
Threat actors are rapidly weaponizing high-risk exploits in the wild using AI tools and LLMs to automate analysis of vulnerabilities, rather than discovering new zero-days.
Click on any entity below to view its context and source!
organisation
Google
As an example, Google pointed to CVE-2026-1731 — a vulnerability in BeyondTrust software
spotlighted
by federal cyber defenders in February.
organisation
CVE-2026
As an example, Google pointed to CVE-2026-1731 — a vulnerability in BeyondTrust software
spotlighted
by federal cyber defenders in February.
organisation
BeyondTrust
As an example, Google pointed to CVE-2026-1731 — a vulnerability in BeyondTrust software
spotlighted
by federal cyber defenders in February.
organisation
POC
“It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days,” the researchers said.
organisation
SPARKRAT
“GTIG observed these threat actors collectively conduct a variety of post-exploitation activities, including privilege escalation, data exfiltration, and dropping secondary payloads including SNOWLIGHT, SPARKRAT, and cryptominers.”
organisation
GTIG
In a report on Wednesday, GTIG said the increase in vulnerability exploitation in 2026 “is driven by the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-days.”
the first eight months of 2026
Threat actors exploited 141 distinct vulnerabilities in the first eight months of 2026, more than double the number seen in all of 2025.
Click on any entity below to view its context and source!
general_metric
141 distinct exploited vulnerabilities
In addition, GTIG recorded 141 distinct exploited vulnerabilities in the first eight months of 2026, more than the 127 seen in all of 2025.
the first three months of 2026
CISA reported a 263% increase in annual CVE submissions between 2020 and 2025, with the first three months of 2026 seeing one-third more submissions than during the same period in 2025.
Click on any entity below to view its context and source!
industry
Technology
The National Institute of Standards and Technology’s National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 one-third higher than during the same period in 2025, CISA said.
attribution
CISA
The National Institute of Standards and Technology’s National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 one-third higher than during the same period in 2025, CISA said.
general_metric
263 %
The National Institute of Standards and Technology’s National Vulnerability Database program reported a 263% increase in annual CVE submissions between 2020 and 2025, with submissions in the first three months of 2026 one-third higher than during the same period in 2025, CISA said.
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
Vulnerabilities whose description mentions the Linux kernel alone generated roughly 5,000 CVEs between January and August, with no in-the-wild zero-day exploitation observed.
Intelligence Sources
SecurityWeek
2026-09-30
TheRecord
2026-09-30
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T11:21
Comprehensive Tactical Telemetry
Highly Correlated Entities
14x
timeline
Temporal Reference
2025/09/30
date
10x
general metric
%
26
%
10x
organisation
Identified Entity
BeyondTrust Privileged Remote Access and Remote Support
entity
5x
attribution
Attributing Entity
Google Threat Intelligence Group
authority
3x
tactic
Cyber Operation Type
Remote Code Execution
tactic
Contextual Telemetry
Context Block
7 METRICS
infrastructure
Affected Product
Linux
software
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
vulnerability
Exploited CVE
CVE-2026-1731
cve
general metric
Distinct Exploited Vulnerabilities
141
distinct exploited vulnerabilities
general metric
August
1,500
august
industry
Targeted Sector
Technology
sector
general metric
Last Year
127
last year
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.