Google’s AI Warning: Known Flaws, Not Zero-Days, Are the Bigger Risk
techradar.com

Google’s AI Warning: Known Flaws, Not Zero-Days, Are the Bigger Risk

Tech News
4 min read

Published by AINave Editorial

TL;DRGoogle’s threat-intelligence team sees a sharper rise in exploitation of known vulnerabilities than in zero-day attacks. Its concern is that AI tools may make it quicker to turn public vulnerability details into working exploits.

Google’s warning about AI and cyber threats centers on a familiar problem: attackers exploiting flaws that are already known. The Google Threat Intelligence Group (GTIG) reported that average monthly in-the-wild exploitation rose from 10.5 vulnerabilities in 2025 to 18 in 2026, while zero-day exploitation increased more modestly, from 8 to 11 per month. The figures point to faster pressure on defenders to address disclosed flaws, rather than a dramatic shift toward attacks on previously unknown bugs. Google’s reported figures and assessment

The growing concern is weaponizing known flaws

GTIG also reported that monthly vulnerability disclosures rose from 5,045 in January 2026 to 10,740 in August. Those are counts at two points in the year, not a full-year comparison. The article says the number of exploited high-risk flaws doubled year-on-year, while GTIG characterized the zero-day increase as marginal. The disclosure and exploitation figures

The distinction matters because a vulnerability can become dangerous after its details are public. Attackers do not necessarily need to discover a new flaw if they can use information about a patch, affected product versions, a disclosure, or proof-of-concept code to work out how to exploit it.

GTIG’s explanation is a hypothesis about efficiency, not proof that AI caused the increase. The group says threat actors may use large language models and other AI tools to automate comparisons among product versions, patches, disclosures, and proof-of-concept code, helping them weaponize known, or “n-day,” vulnerabilities more quickly. GTIG’s assessment of how AI may assist that process

A disclosed flaw can still have a short runway

One example in the report, as described by TechRadar, is CVE-2026-1731, a command-injection flaw in BeyondTrust products discovered by a third-party AI research agent. GTIG said attackers began exploiting it within days of public disclosure in campaigns involving privilege escalation, data theft, and malware deployment. That example shows how quickly a known flaw can attract attackers; it does not establish that every AI-discovered vulnerability will be exploited on the same schedule. The BeyondTrust vulnerability example

The article also reports that 50% of vulnerabilities discovered with AI resulted in remote code execution, compared with 26% across the broader vulnerability ecosystem. That comparison describes the reported outcomes of those vulnerability sets; it does not show that AI itself made a flaw more severe. The remote-code-execution figures

Triage matters more than patching everything equally

GTIG recommends moving away from broad, unprioritized mass patching toward threat-intelligence-driven triage, targeted edge defenses, and automated remediation. The logic is that when attackers can act quickly on public information, teams need to identify which known flaws are relevant and exposed in their own environments, rather than treating every patch as equally urgent. GTIG’s recommended defensive approach

The report forecasts that vulnerability discovery and exploitation will continue to grow in the short to medium term. That is an expectation, not a measured outcome. The more immediate signal is the reported rise in exploitation of known flaws: AI’s security impact may show up less as a flood of novel bugs than as less time to respond once a vulnerability becomes public. GTIG’s forecast and the reported trend

FAQs

GTIG says attackers may use LLMs and other AI tools to compare product versions, patches, vulnerability disclosures, and proof-of-concept code to help weaponize known flaws. The group presents this as a possible efficiency gain, not proof that AI caused the increase in exploitation. GTIG’s assessment

Sources

Latest Tech News