Cookie Consent by Free Privacy Policy Generator

Google research shows AI-discovered vulnerabilities more likely to enable remote code execution

Google Threat Intelligence Group has published research examining vulnerability disclosure and exploitation trends between January 2025 and August 2026. The research found that monthly CVE disclosures doubled during this period, rising from 5,045 in January to 10,740 in August. Whilst only 0.23% of disclosed vulnerabilities were exploited, the research identified a notable pattern: vulnerabilities discovered using AI research methods are significantly more likely to enable remote code execution compared to those found through traditional methods. Google also reported that attackers exploited one AI-discovered vulnerability within four days of its public disclosure, suggesting that the pace of exploitation is accelerating alongside the pace of discovery.

Why this matters for UK organisations

This research changes the assumptions organisations can make about vulnerability management. Traditionally, security teams have relied on the fact that most disclosed vulnerabilities are never exploited, allowing them to prioritise patching based on CVSS scores, asset criticality and known exploitation. If AI tools are discovering vulnerabilities that are both more severe and more likely to be exploited quickly, then the window for defensive action is narrowing. For UK businesses, this reinforces the importance of having mature vulnerability management processes that can respond to disclosures within days rather than weeks, particularly for internet-facing systems. It also highlights the need to understand which vulnerabilities are being prioritised by attackers and why, rather than treating all high-severity CVEs as equally urgent. The four-day exploitation timeline reported by Google is particularly significant: it suggests that organisations may have less time than previously assumed to patch critical systems before exploitation begins.

What to review

UK organisations should review whether their vulnerability management processes are designed to handle faster disclosure-to-exploitation timelines. It is worth checking whether security teams have the tools, authority and support needed to patch critical systems within 72 hours of a disclosure, and whether that expectation is clearly understood across IT, development and leadership teams. Many organisations struggle to patch quickly not because of technical limitations but because of unclear ownership, change control processes that were designed for a slower threat environment, or a lack of agreement on what constitutes a critical vulnerability. This is also a prompt to review whether vulnerability scanning covers all internet-facing systems, whether there is a clear process for prioritising patches based on exploitation risk rather than CVSS scores alone, and whether security teams have access to threat intelligence that helps them understand which vulnerabilities are being actively targeted. Organisations should also consider whether they are monitoring for exploitation attempts, not just scanning for vulnerabilities, so that they can detect and respond if patching is delayed.

Source: Help Net Security

News and blog posts
Today's brief reflects a pattern UK organisations will recognise: the need to...
The National Cyber Security Centre has issued urgent guidance calling on UK...
Google Threat Intelligence Group has published research examining vulnerability...
Cryptocurrency exchange Bitget has confirmed that attackers who stole $387.5...