Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
Google Threat Intelligence Group says vulnerability disclosures more than doubled during the first eight months of 2026, rising from 5,045 in January to 10,740 in August as artificial intelligence changes the pace of vulnerability discovery and exploitation.
The monthly total exceeded 10,000 in both July and August, reaching 10,477 in July and 10,740 in August. GTIG found that AI is also changing the types and risk profiles of vulnerabilities being discovered.
The increase in disclosure volume does not mean every vulnerability presents the same level of risk. GTIG found that only 0.23 percent of vulnerabilities disclosed in 2026 were observed in active exploitation, roughly one in 431.
Between January and August 2026, GTIG recorded 141 vulnerabilities that had been disclosed and exploited. That total already exceeded the 127 exploited vulnerabilities recorded during all of 2025.
Researchers said the increase is being driven primarily by faster weaponization of high-risk n-day vulnerabilities rather than by a dramatic surge in previously unknown zero-day flaws.
Zero-days are vulnerabilities exploited before the affected vendor has publicly disclosed the flaw or made a fix available. N-days are vulnerabilities that have already been publicly disclosed, often with patches or technical details available for analysis.
GTIG said it is possible that threat actors are finding it more accessible or efficient to use artificial intelligence and large language models to automate analysis of product versions, patches, vulnerability disclosures, and proof-of-concept code to rapidly weaponize n-day vulnerabilities.
GTIG said vulnerability discovery and exploitation are expected to continue growing in the short to medium term.
One example cited by GTIG involved CVE-2026-1731, a vulnerability affecting BeyondTrust software that was identified autonomously by the third-party research agent Hacktron AI.
One threat cluster began exploiting CVE-2026-1731 within four days of disclosure. Five additional threat clusters were observed using the vulnerability within seven days.
The activity demonstrated how quickly a high-risk vulnerability affecting enterprise infrastructure can move from disclosure into active exploitation.
GTIG observed post-exploitation activity associated with the flaw that included privilege escalation, data exfiltration, secondary payload deployment, and cryptocurrency mining. Malware identified during those campaigns included SNOWLIGHT and SPARKRAT.
The BeyondTrust case also illustrates the dual role AI can play in cybersecurity.
Autonomous research systems can help defenders identify serious software weaknesses faster, but the public disclosure of those weaknesses can also give attackers information they can process with AI-assisted tools.
GTIG found that attackers continue to concentrate on systems positioned at the edge of enterprise networks. Approximately 14 percent of vulnerabilities exploited between January and August affected edge and security appliances.
Those systems can include network infrastructure and other externally accessible services that sit between internal enterprise environments and the public internet.
Vulnerabilities affecting perimeter systems are attractive to attackers because successful exploitation can provide an initial point of access without first requiring compromise of an internal workstation.
Google researchers also found that AI-assisted discovery produced proportionally fewer Low-Risk vulnerabilities and proportionally more Medium- and High-Risk vulnerabilities.
GTIG uses its own vulnerability risk-rating system, separate from CVSS severity. High-Risk vulnerabilities increased sharply during 2026, rising from 131 disclosures in January to 350 in August.
A portion of the disclosure increase came from concentrated activity involving specific vendors.
GTIG identified router manufacturer TOTOLINK and Oracle among vendors contributing significant numbers of disclosed vulnerabilities during the year. Large disclosure cycles from individual vendors can cause monthly totals to rise sharply, so overall CVE volume does not always reflect an equal increase in risk across the entire software ecosystem.
The broader vulnerability environment is expanding at the same time, placing additional pressure on vulnerability-management programs.
Security teams cannot realistically treat tens of thousands of newly disclosed vulnerabilities as equally urgent. Prioritization depends on factors such as active exploitation, internet exposure, affected asset importance, exploit reliability, authentication requirements, and whether the vulnerable system controls access to other parts of the network.
GTIG’s findings indicate that artificial intelligence is making vulnerability prioritization more time-sensitive. A publicly disclosed flaw affecting exposed enterprise infrastructure may attract attacker attention within days, placing greater pressure on organizations that depend on long patching cycles.
The shift does not mean AI has replaced human attackers or automated the entire exploitation process. AI can reduce the effort required for vulnerability research, patch analysis, exploit development, and target identification.
For defenders, the central issue is no longer simply the growing number of vulnerabilities being disclosed. The more important change is how quickly certain high-value flaws can move from public disclosure into active exploitation.
Organizations that maintain accurate asset inventories, identify exposed systems, monitor actively exploited vulnerabilities, and shorten remediation timelines will be better positioned to respond as AI continues to compress the vulnerability lifecycle.
Google Threat Intelligence Group — Vulnerability Discovery and Exploitation Trends in the AI Era, September 30, 2026. Written by Robin Grunewald, Supriya Mazumdar, and Kelli Vanderlee. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



