AI-Driven Vulnerability Discoveries Skyrocket as Threats Multiply
A new report from Google's Threat Intelligence Group reveals that monthly software vulnerability disclosures have doubled between January and August, reaching 10,740 in August. This surge is attributed to the increasing use of artificial intelligence (AI) in vulnerability discovery, which has changed the types of flaws being uncovered.
GTIG found that half of the vulnerabilities discovered by AI agents allow for remote code execution, a much higher rate than conventional disclosures. The report also notes that automated identifier assignment in open-source ecosystems can inflate raw totals, leading to an overestimation of vulnerability numbers.
The data shows that while 141 newly disclosed vulnerabilities were exploited in the wild between January and August, this number is relatively small compared to the total number of disclosures. Zero-day exploitation has increased, with 22 zero-days discovered in August alone, but GTIG notes that most growth comes from n-days, or flaws that attackers exploit once they are public and usually already patched.
The report also highlights the role of large language models in comparing product versions and patches, enabling attackers to quickly turn known flaws into working exploits. GTIG advises organizations to prioritize targeted defenses at the edge and let threat intelligence decide which vulnerabilities to fix first, rather than engaging in mass patching.