Vulnerability disclosures hit 10,740 in August as AI speeds up exploitation
Google's Threat Intelligence Group said on Wednesday that monthly vulnerability disclosures doubled between January and August, peaking at 10,740 last month, with AI agents now doing much of the discovery and weaponisation work.

The number came in a GTIG report published on 30 September. Disclosures started the year at 5,045 in January and passed 10,000 in both July and August, according to The Record. The count of distinct vulnerabilities disclosed and exploited during those eight months already exceeds the total for all of 2025. There have been 141 exploited vulnerabilities this year, against 127 last year.
GTIG's framing matters more than the headline figure. The researchers say the rise in 2026 "is driven by the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-days." In other words, attackers are getting faster at turning already-patched bugs into working attacks.
Kelli Vanderlee, a senior analyst at GTIG, told The Record the team expects AI-assisted discovery and exploitation to keep growing in the short to medium term. The report suggests threat actors find it more efficient to use LLMs to diff product versions, patches and disclosure notices against proof-of-concept code than to hunt for new zero-days.
One bug, six clusters, seven days
The report's worked example is CVE-2026-1731, a flaw in BeyondTrust software that US federal cyber defenders flagged in February. GTIG says the bug was found autonomously by a third-party research agent called Hacktron AI. Within four days of public disclosure, one threat cluster was exploiting it. Five more followed within seven days. The post-exploitation activity included privilege escalation, data exfiltration and secondary payloads named SNOWLIGHT, SPARKRAT and cryptominers.
That sequence is the story: an autonomous agent finds the flaw, the patch ships, and attackers weaponise the gap in days. The researchers said many of this year's disclosures came from a handful of vendors, including router firmware maker Totolink and Oracle.
The GTIG data lands in the same week as several open source projects pushing back with tooling of their own. On 30 September, Archestra published OpenAPPA, a deterministic guardrail layer that sits between an agent and its tools and checks each call against a declarative policy written in TOML. The project's own benchmarks claim no scored attack succeeded in 1,320 evaluations while completing 88 to 90 percent of tasks, compared with 31 percent of attacks succeeding against Microsoft's FIDES in the same tests. Those are vendor numbers from a GitHub repository, not independent results.
A second effort, UAI, published the same day, takes a different angle: giving each agent an identity bound to an accountable owner, with time- and jurisdiction-bounded authorisation and signed action attestations that third parties can verify. Its README is careful to state that the protocol does not claim an agent is safe, only that its actions are attributable.
Neither project addresses the discovery pipeline itself. That is the harder problem, and the one GTIG's numbers describe.
The disclosure side is also under strain
Open source maintainers have their own version of this. The OpenSSL project published an advisory on 29 September for CVE-2026-84782, a high-severity DTLS flaw that can leak heap memory. A separate advisory from the LiteLLM project, GHSA-7hp6-4w63-5g45, describes a privilege escalation to proxy admin that can lead to remote code execution.
The volume problem has attracted attention beyond the vendors. The music industry group IFPI used its submission to the 2027 EU Counterfeit and Piracy Watch List, reported by TorrentFreak, to name the open source YouTube downloader yt-dlp as a stream-ripping service. IFPI argues the tool is "difficult to contain and/or remove" because of its open source nature and developer community. The submission names four maintainers by their GitHub handles and asks for no specific action against them.
Elsewhere, China's domestic model hubs are positioning themselves as alternatives to Hugging Face, which Beijing blocked in 2023. Alibaba's ModelScope hosts more than 170,000 models and OSChina's MoArk about 20,000, Rest of World reported. OSChina chief executive Xu Yong told the outlet that not everyone can use a VPN all the time.
The throughline is uncomfortable. The same agentic capability that GTIG says is accelerating exploitation is also being pitched as the fix, by OpenAPPA, by UAI and by a growing pile of startups. The 10,740 figure is the only hard number in the argument so far.
Sources
11- 01Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitationEN
- 02OpenAPPA: Deterministic guardrails that don't break agentsEN
- 03UAI - An open protocol for identity and accountability of AI agentsEN
- 04OpenSSL Security Advisory: DTLS heap memory leak (CVE-2026-84782)EN
- 05New LiteLLM Vulnerability: Privilege Escalation to Proxy Admin and RCEEN
- 06IFPI Wants Open Source YouTube Downloader Yt-Dlp on EU Piracy Watch ListEN
- 07The open-source AI platforms vying to become China's Hugging FaceEN
- 08OpenAI's dirty deeds Down Under included security bypass attempts, using exposed keys, source code siphonEN
- 09US trade regulator opens investigation into AI giants including Anthropic and OpenAIEN
- 10FTC is investigating OpenAI, Anthropic and other AI companies over product risksEN
- 11"An AI did it" is no defense, says nonprofit suing OpenAI over Hugging Face hackEN
All figures and quotations in this text come from the sources listed below.
Content prepared by the editorial team with AI assistance.
Comments
0- No comments yet — be the first.