The Evolving Role of AI in Cyberattacks

Artificial Intelligence is significantly altering the cybersecurity landscape, making it easier and faster for threat actors to exploit software vulnerabilities. According to a recent report by Google’s Threat Intelligence Group (GTIG), the primary danger does not lie where many might expect—in the discovery of secret 'zero-day' exploits—but rather in the accelerated weaponization of already known vulnerabilities, known as 'n-days'.


Surge in Vulnerability Discovery and Exploitation

The research, titled Vulnerability Discovery and Exploitation Trends in the AI Era, reveals a measurable shift in how software flaws are handled. Throughout 2026, the volume of discovered vulnerabilities saw a dramatic increase, jumping from 5,045 in January to 10,740 in August. Correspondingly, instances of these flaws being exploited in the wild rose from an average of 10.5 per month in 2025 to 18 per month in 2026.


While one might assume AI is being used to hunt for unknown security holes, the data suggests otherwise. Google noted only a slight uptick in zero-day exploitation, rising from 8 per month last year to 11 per month currently. Instead, AI is acting as a force multiplier for attackers looking to capitalize on publicized flaws.


"It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days," the report noted.

Impact on Security Defense

AI is also proving to be a double-edged sword, offering benefits to security defenders as well. Google observed that vulnerabilities identified with the help of AI tend to be more severe, with 50% of them resulting in remote code execution (RCE), compared to 26% of vulnerabilities discovered through traditional means. This allows defenders to focus their resources on higher-risk issues.


However, attackers are equally agile. The report highlighted CVE-2026-1731, a command-injection flaw in BeyondTrust products discovered by an AI research agent, which was weaponized by threat actors mere days after its public disclosure to facilitate data theft and malware deployment.


Strategic Shift Required for Organizations

As the speed of both discovery and exploitation continues to climb, Google stresses that standard patching protocols are no longer sufficient. Organizations must evolve their defense strategies:

  • Move away from unprioritized, mass-patching programs.
  • Adopt intelligence-driven vulnerability management.
  • Combine targeted edge-defense with automated, agentic remediation.

In the short to medium term, GTIG expects these trends to intensify as adversaries further experiment with AI-powered tools to both uncover and exploit critical infrastructure, runtime environments, and core libraries.