Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Google Threat Intelligence Group (GTIG) says vulnerability disclosures and observed exploitation both increased in its 2026 data. Its warning is narrower than the headline suggests: attackers may be using large language models (LLMs) and other AI tools to analyze patches, product versions and proof-of-concept code faster, helping them exploit already disclosed flaws—not necessarily to discover more zero-days. GTIG presents that as a possibility, not a proven cause of the increase.
What Google’s warning means
In a September 30, 2026 post, GTIG writes that it is “possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools” to automate analysis of product-version differences, patches, vulnerability announcements and proof-of-concept code. The proposed outcome is faster weaponization of “n-day” vulnerabilities: flaws that have already been disclosed, rather than previously unknown zero-days.
That distinction matters. GTIG does not say its data proves attackers used AI to cause the observed rise in exploitation. The report describes a plausible way AI could lower the effort or time needed to turn public vulnerability information into attacks.
What changed in GTIG’s data
GTIG analyzed vulnerability disclosures from January 1, 2025 through August 31, 2026. Its figures show higher monthly disclosure and observed exploitation counts in 2026, but they measure different things and should not be treated as a direct causal link.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
| Measure | GTIG’s reported figure | How to read it |
|---|---|---|
| Monthly vulnerability disclosures | 5,045 in January 2026; 10,740 in August 2026 | Disclosure volume is not the same as the number of flaws attackers can exploit. |
| Observed exploited vulnerabilities | Average of 10.5 per month in 2025; 18 per month from January through August 2026 | This is GTIG’s observed count, not a count of every attempted attack. |
| Zero-days exploited | Average of 8 per month in 2025; 11 per month from January through August 2026; 22 in August 2026 | Zero-day exploitation increased more modestly than the broader observed exploitation count. |
| Share of observed exploited vulnerabilities that were zero-days | 62% from January through August 2026 | The denominator is GTIG’s observed exploited vulnerabilities during that period, not all disclosed flaws. |
These figures are from GTIG’s analysis. They describe what the group observed and counted; they do not establish the odds that a particular vulnerability will be attacked.
Why raw CVE totals can mislead
A rise in assigned Common Vulnerabilities and Exposures (CVE) identifiers does not necessarily mean an equivalent rise in distinct, practically exploitable threats. GTIG warns that automated CVE Numbering Authority assignment policies can inflate raw totals.
As an example, GTIG cites approximately 5,000 CVEs with descriptions containing “Linux Kernel” from January through August 2026. It reports zero observed in-the-wild zero-days in that group. The example illustrates why organizations should not prioritize solely by disclosure counts or assume that every assigned CVE represents an actively exploited vulnerability.
A case where discovery and exploitation followed quickly
GTIG highlights CVE-2026-1731, an unauthenticated OS command-injection vulnerability affecting BeyondTrust Privileged Remote Access and Remote Support. According to GTIG, the third-party research agent Hacktron AI discovered the flaw autonomously. A threat cluster began exploiting it within four days of public disclosure, and GTIG observed five additional clusters within seven days.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
GTIG describes targeted initial-access campaigns followed by activity including privilege escalation, data exfiltration and delivery of secondary payloads. This is an example of a short window between public disclosure and observed exploitation; it does not, by itself, show that the attackers used AI to exploit the flaw.
What GTIG says about AI-assisted vulnerability discovery
GTIG reports an early indicator that AI-discovered vulnerabilities may include proportionally fewer low-risk findings and more moderate-risk findings, along with more vulnerabilities leading to remote code execution. It explicitly treats this as an emerging signal, not an established trend. It does not mean all AI-discovered flaws are severe, or that AI alone explains their characteristics.
Rank #4
GTIG also distinguishes its vulnerability risk ratings from CVSS severity scores. Those are not interchangeable measures, so a risk rating or severity label should be considered alongside exposure and evidence of exploitation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How organizations can respond
GTIG recommends moving away from unprioritized mass-patching toward threat-intelligence-driven triage, targeted edge defense and automated, agentic remediation. For a security team, the practical implication is to keep remediation moving while directing the fastest attention to systems with meaningful exposure and evidence of active exploitation.
Best Value
- Use exploitation evidence to set urgency. Incorporate credible intelligence about in-the-wild exploitation into vulnerability triage rather than treating every new disclosure as equally urgent.
- Account for exposure. Identify vulnerable services reachable at the network edge and apply targeted defenses while fixes are prepared or deployed.
- Automate safely. Use automation or agentic remediation to accelerate repeatable work, with controls appropriate to the system and the change being made.
- Keep patching as a core control. Prioritization is not a reason to leave other vulnerabilities unaddressed; it helps determine what needs action first.
The goal is not to predict whether an attacker used AI. It is to reduce the time an exposed, exploitable system remains vulnerable, especially when credible reporting indicates active exploitation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

