🛡 AI Shrinks the Window Between Patch and Exploit — GTIG Report

Google GTIG published a report covering January 2025 to August 2026: CVE disclosures doubled — from 5,045 per month in January to a peak of 10,740 in August 2026. In the wild, 141 vulnerabilities were exploited over eight months of the year — more than the entire year of 2025 (127).

🌍 AI is changing the threat profile: RCE in 50% of cases for AI findings versus 26% on average. According to GTIG's hypothesis, LLMs automate patch and PoC analysis, accelerating the conversion of known n-days into weapons. 14% of targets are peripheral devices.

👤 Routers, gateways, and services with public management interfaces are the main target, and they need to be patched faster. But don't be alarmed by the 'doubling of CVEs': only 0.23% (1 in 431) are actually exploited.

Source 1: https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era/ Source 2: https://news.ycombinator.com/item?id=49940122