Google: security flaw disclosures double to 10,000 per month as AI fuels exploitation

What happened
Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned. Total vulnerability disclosures began the year at 5,045 in January and had jumped to more than 10,000 for July and August. Google is an Internet and software company based in Mountain View.
They noted that beyond the overall number of bugs being found, the number of distinct vulnerabilities disclosed and exploited during the eight month period surpassed the totals for all of 2025. There have already been 141 exploited vulnerabilities this year after 127 last year.
Zero-days are vulnerabilities that are exploited before they are known to vendors and n-days are vulnerabilities that have been patched and publicly disclosed. The researchers found that hackers are getting better at using artificial intelligence to scan patches and exploit critical bugs.
The bug was found autonomously by a third-party research agent Hacktron AI. In a report on Wednesday, GTIG said the increase in vulnerability exploitation in 2026 βis driven by the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-day (a flaw already being used in attacks before a fix exists)s.β
Key facts
- The researchers β found: that hackers are getting better at using artificial intelligence to scan patches and exploit critical bugs
- The bug was β found: autonomously by a third-party research agent Hacktron AI
Sources & evidence
- The Record Reporting source
Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation β
https://therecord.media/google-vulnerabilities-cyberattacks-ai