Google Threat Intelligence Group (GTIG) reported that vulnerabilities likely discovered with AI are disproportionately severe: 50% enabled remote code execution (RCE), compared with 26% of other CVEs. Vulnerability disclosures rose from 5,045 in January 2026 to 10,740 in August, while attackers exploited 141 distinct vulnerabilities in the wild during the first eight months of the year. GTIG assesses that adversaries may be using LLMs and other AI tools to rapidly analyze patches, vulnerability disclosures, and proof-of-concept code to weaponize known flaws.
The report highlighted CVE-2026-1731, an unauthenticated command-injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support. One threat cluster exploited the flaw within four days of disclosure, followed by five more clusters within seven days. GTIG identified agent-orchestration frameworks, AI inference infrastructure, and internet-facing edge devices as concentrated risk areas, but cautioned that confirmed exploitation of AI-discovered vulnerabilities remains an early indicator rather than a firmly established trend; it had not observed zero-day exploitation of AI infrastructure.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Google Threat Intelligence Group published research finding that 50% of vulnerabilities it assessed as likely AI-discovered enabled remote code execution, compared with 26% of other CVEs. GTIG characterized confirmed exploitation of AI-discovered flaws as an early indicator rather than an established trend.
GTIG observed 10,740 vulnerability disclosures and 22 zero-days exploited in August 2026. It had not observed zero-day exploitation of AI infrastructure as of that month.
GTIG reported 10,477 vulnerability disclosures in July 2026, more than double the January total.
GTIG recorded 5,045 vulnerability disclosures in January 2026, the baseline for a subsequent rise in reported CVE volume.
Citrix fixed two exploited NetScaler zero-day vulnerabilities. GTIG and Mandiant tracked one of the flaws in active attacks, and Mandiant advised customers to investigate for compromise before patching.
Hacktron AI autonomously discovered CVE-2026-1731, an unauthenticated OS command-injection vulnerability in BeyondTrust Privileged Remote Access and Remote Support. One threat cluster exploited it within four days of public disclosure and five additional clusters did so within seven days; the sources do not state the disclosure date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceinfosecurity-magazine.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.