GTIG Sees AI Pushing Flaws Into Faster Exploitation
Google Threat Intelligence Group said on September 30 that vulnerabilities it judged likely AI-discovered were twice as likely to lead to remote code execution, and that exploited flaws rose faster in 2026 than zero-days. It tied that shift to faster disclosure-to-exploit cycles, with one AI-found bug, CVE-2026-1731 in BeyondTrust Privileged Remote Access and Remote Support, weaponized within days.
The pattern is plain: once a patch or proof of concept is public, AI tools can help turn it into working exploit code quickly, so the danger window moves into the days after disclosure, not just the zero-day phase. GTIG also said edge and security appliances remain a major target class, and that many of the exploited flaws it tracked there were high or critical risk.
For teams that depend on rapid remediation of internet-facing appliances and remote-support platforms, the practical exposure is shrinking time, not just more bugs. The reporting does not show that AI creates every exploit, but it does show that disclosed fixes are becoming usable faster, especially where a public-facing device can be reached directly.
GTIG investigated vulnerability disclosure and exploitation statistics and found that AI is measurably changing the pace of vulnerability discovery, exploitation, and the types of vulnerabilities being discovered.