AI Identifies Critical Vulnerabilities Cybercriminals Target

www.news4hackers.com-ai-identifies-critical-vulnerabilities-cybercriminals-target-ai-identifies-critical-vulnerabilities-cybercriminals-target

According to findings from the Google Threat Intelligence Group (GTIG).

The vulnerabilities identified by artificial intelligence systems are the primary targets for malicious actors, according to findings from the Google Threat Intelligence Group (GTIG). Analysis of vulnerability disclosure and exploitation patterns between January 2025 and August 2026 reveals that threat groups rapidly exploit flaws discovered through AI-driven research. This trend underscores a growing reliance on automated tools to analyze security disclosures and accelerate attack deployment.

Key Findings

Surge in CVE Disclosures

Monthly CVE disclosures saw a significant increase in 2026, rising from 5,045 in January to 10,740 by August. Despite this surge, only 0.23% of disclosed vulnerabilities were observed in active exploitation, equating to approximately one in 431 cases.

Exploitation Rates

GTIG documented 141 exploited vulnerabilities between January and August 2026, surpassing the 127 recorded throughout all of 2025. The average monthly count of zero-day exploits rose from eight in 2025 to 11 in 2026, with the majority of this growth attributed to n-day vulnerabilities.

AI’s Role in Exploitation

Researchers suggest that threat actors are leveraging large language models (LLMs) and AI tools to analyze patches, disclosure announcements, and proof-of-concept code, enabling faster weaponization of recently disclosed flaws.

Risk Ratings

High-Risk Vulnerabilities

GTIG employs proprietary risk ratings for vulnerabilities, distinct from CVSS severity scores. High-risk vulnerabilities identified by the group increased from 28 in 2025 to 75 in the first eight months of 2026.

AI-Discovered Flaws

AI-discovered flaws demonstrated a higher likelihood of enabling remote code execution compared to vulnerabilities found through traditional methods. Specifically, 50% of AI-identified vulnerabilities led to remote code execution, versus 26% for non-AI discoveries.

Case Studies

CVE-2026-1731

The unauthenticated OS command injection vulnerability CVE-2026-1731 in BeyondTrust Privileged Remote Access and Remote Support, uncovered by the Hacktron AI research agent. Threat actors exploited this flaw within four days of its public disclosure, deploying it in targeted initial-access campaigns. Subsequent attacks involved privilege escalation, data exfiltration, and the deployment of payloads such as SNOWLIGHT, SPARKRAT, and cryptominers.

AI-Related Vulnerabilities

Agent Orchestration Frameworks

Half of these disclosures targeted agent orchestration frameworks like Flowise and Langflow, where attackers exploit code execution nodes through prompt injection or malicious workflow JSONs.

Inference and Serving Software

Inference and serving software such as vLLM, Ollama, and LiteLLM accounted for 212 vulnerabilities in 2026, with nearly 25% stemming from unauthenticated API endpoints or server-side request forgery vulnerabilities.

Recommendations

GTIG anticipates continued growth in vulnerability discovery and exploitation, urging organizations to shift from untargeted patching strategies to threat-intelligence-driven prioritization. Recommendations include deploying targeted edge defenses and automated, agent-based remediation systems to mitigate risks associated with rapid vulnerability exploitation.


Blog Image

About Author

en_USEnglish