Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

https://www.securityweek.com/wp-content/uploads/2025/07/AI-Chatbot-GenAI-artificial-intelligence.jpg

The number of vulnerabilities disclosed each month doubled in 2026, and the monthly average of vulnerabilities exploited in the wild nearly doubled, according to a new report from Google Threat Intelligence Group (GTIG).

Analyzing disclosures from January 2025 through August 2026, GTIG found that monthly disclosures rose from 5,045 in January 2026 to 10,477 in July, peaking at 10,740 in August.

“We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered,” GTIG says.

The researchers caution that raw volume can be misleading, as automated CVE assignment in open source ecosystems can inflate the numbers. Vulnerabilities whose description mentions the Linux kernel alone generated roughly 5,000 CVEs between January and August, with no in-the-wild zero-day exploitation observed.

High-risk disclosures, based on GTIG’s own ratings rather than CVSS, grew 167%, from 131...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more