Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

    October 7, 2026

    Someone Scraped 5.6 Billion TikTok Videos and Put the Data on Hugging Face for Free

    October 7, 2026

    Physicists just saw quarks make waves in the Big Bang’s primordial soup

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
    • Someone Scraped 5.6 Billion TikTok Videos and Put the Data on Hugging Face for Free
    • Physicists just saw quarks make waves in the Big Bang’s primordial soup
    • Stop worrying about my AI, says multibillionaire Sam Altman. So we bear the risks and he keeps the money | Chris Stokel-Walker
    • Hunter Valley community group wins landmark high court climate change case over coalmine | Environment
    • How to find out if Amazon thinks you have ‘flat buttocks’
    • A Developer’s Guide to Laya: Zero-Shot Decisions and Calibration
    • AI accelerates n-day attacks, as flaw disclosures and exploits double
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AI accelerates n-day attacks, as flaw disclosures and exploits double

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 7, 2026 Cybersecurity No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers are increasingly weaponizing already-disclosed flaws rather than new zero-days, and AI tools may be accelerating how quickly they do it.

    According to a report from Google’s Threat Intelligence Group (GTIG), attackers have exploited more vulnerabilities in the wild thus far this year than they did all of last year. With the number of flaws disclosed each month sharply rising, AI tools are helping reduce the time it takes to write working exploits for publicly disclosed bugs.

    GTIG recorded 141 flaws exploited between January and August 2026, compared to 127 in all of 2025, with monthly vulnerability disclosures doubling over the period, from 5,045 in January to 10,740 in August.
    That rise in the monthly exploitation rate, from 10.5 per month last year to nearly 18 in 2026, greatly eclipsing that of exploited zero-days, which increased marginally from 8 per month in 2025 to 11 thus far this year.

    Foundry’s forthcoming Security Priorities survey finds security leaders significantly more concerned about n-days than zero-days, with respondents expressing high concern about software n-day exploitation (38%) and network n-day exploitation (37%) versus zero-day exploits (25%).

    “It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools to automate analysis of differences between product versions, patches, vulnerability disclosure announcements, and Proof-of-Concept (POC) code to rapidly weaponize n-days, rather than to discover new zero-days,” the GTIG researchers wrote in their report.

    The type of exploited vulnerabilities also stands out, with high-risk flaw exploits doubling from 28 in 2025 to 75 in the first eight months of 2026. This aligns as well with a surge in high-risk vulnerability disclosures as the year has progressed, from 131 in January to 350 in August.

    “While this is of course concerning, it’s hardly unexpected,” Steve Povolny, vice president of AI strategy and security research at Exabeam, tells CSO. “We know by now that AI models are able to achieve speed, scale, and efficiency that few, if any, human beings are capable of. Inevitably, discovering known flaws and finding ways to exploit them is par for the course when it comes to AI.”

    A flood of new CVEs

    While the number of new vulnerabilities doubled, and some of that rise is driven by use of AI models and agents, GTIG warns that automated CVE Numbering Authority assignment policies across open-source ecosystems might inflate the baseline.

    For example, vulnerabilities whose descriptions mentioned the Linux kernel alone produced roughly 5,000 CVEs between January and August with no zero-days exploited in the wild. Meanwhile, other single vendors accounted for unusually big spikes in high-risk flaws at various points during the year.

    Totolink patched 75 high-risk flaws in its consumer router firmware in April and May, driving a midyear spike in command execution vulnerabilities, while Oracle’s quarterly Critical Patch Update across middleware such as WebLogic and Coherence, combined with Linux kernel network driver advisories, contributed 128 high-risk vulnerabilities in August alone.

    When it comes to exploitation, the proportion of disclosed flaws that are exploited remains very small at 0.23% or roughly 1 in 431. But GTIG’s researchers noticed a monthly trend where indexed growth in CVE exploitation nearly perfectly mirrors indexed growth in vulnerability disclosure, which suggests exploitation doesn’t necessarily outpace vulnerability disclosure growth.

    In fact, other companies who track vulnerabilities previously noted an increase in disclosure compared to exploitation. For example, vulnerability intelligence firm VulnCheck found in its H1 2026 report that the ratio of exploited to disclosed vulnerabilities dropped to 1.4% after peaking at 2.7% in 2023, suggesting that disclosure volume grew much faster than exploitation. On the other hand, the median time from a CVE’s publication to confirmed exploitation fell from 120 days in 2025 to 80 days in the first half of 2026, potentially highlighting the impact of AI agents in attacks.

    Attackers continue to target the perimeter

    Edge and security appliances accounted for 14% of the vulnerabilities exploited from January to August, and two-thirds of those flaws had high or critical severity, GTIG noted. Meanwhile enterprise directory and collaboration hubs accounted for another 11%. Network-edge appliances have been one of the leading initial access vectors for the past two years, targeted by both state-sponsored APT groups as well as ransomware gangs.

    Attackers target unauthenticated public management interfaces in particular because they reach systems that enterprise endpoint detection and response (EDR) agents can’t see, the GTIG researchers said: “While CVE discovery volume metrics surge, adversary exploitation activity remains concentrated in perimeter appliances and exposed enterprise services.”

    AI-discovered flaws have higher severity ratings

    It’s hard to determine which vulnerabilities were found with the assistance of AI models, as this information is not disclosed in advisories and the practice has not yet been standardized. But of those GTIG determined were discovered by AI agents, over half were medium severity and above, compared to under a third across the total pool of disclosed vulnerabilities. Furthermore, 50% of AI-discovered flaws include remote code execution as an impact compared to 26% across conventional disclosures.

    “This distribution largely likely reflects how research programs scope and deploy these systems,” the researchers said. “Rather than running broad, automated scans for cosmetic flaws or compliance warnings, researchers deliberately prompt and task autonomous agents with auditing critical infrastructure and sensitive privilege boundaries, focusing on high-impact findings.”

    When it comes to exploitation, there is evidence that attackers are employing AI agents to analyze software patches and develop exploits for n-day flaws. For example, in May, GTIG reported that a North Korean state-linked group tracked as APT45 sent thousands of prompts to Gemini to analyze known vulnerabilities and validate proof-of-concept exploits.

    An OS command injection flaw in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) that was discovered with the help of an AI research agent by Hacktron AI was weaponized for targeted initial-access campaigns within four days of public disclosure. Within seven days GTIG observed six total threat clusters exploiting the flaw.

    Companies need AI-assisted vulnerability management

    As both vulnerability discovery and exploitation are expected to grow in the medium term, companies must transition from patching vulnerabilities en masse to triaging them using threat intelligence and deploying automatic agentic remediation.

    Detectify, a company that maps and measures the external attack surface exposure for its customers, found that the vast majority of critical and high-severity flaws in internet-facing assets stay exposed for more than 90 days. Among organizations monitored by the security firm over 12 months, their verified internet-facing domains grew by 20% in the US and 14% in the UK, meaning that new exposure is being created before the existing exposure can be secured.

    On Sept. 22, the Cybersecurity and Infrastructure Security Agency (CISA) published a framework for moving the CVE Program from what it calls a growth era into a quality era, citing more than 67,000 CVEs published in 2026 through Sept. 18 and a projected 96,000 by year-end. It proposes measures such as improving record quality and completeness as well as API responsiveness and system uptime.
    However, Farzad Bakhtiar, senior director at Flashpoint, warns that a well-formed record is not necessarily an actionable one.

    “Security teams need to know whether a vulnerability has a working exploit, whether attackers are using it, whether it touches their exposed assets, and whether there’s a fix,” he tells CSO. “With CVE volume on pace to approach 100,000 this year, and many vulnerabilities never receiving a CVE at all, that context is what turns vulnerability data into a prioritization decision.”

    accelerates attacks Disclosures double exploits Flaw Nday
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

    Ninja Forms plugin flaw exploited to hack WordPress sites

    What exactly is ISOC? And what does it mean for you?

    The AI app builder your team trusts has a root-level backdoor

    Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

    Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

    October 7, 2026

    Someone Scraped 5.6 Billion TikTok Videos and Put the Data on Hugging Face for Free

    October 7, 2026

    Physicists just saw quarks make waves in the Big Bang’s primordial soup

    October 7, 2026

    Stop worrying about my AI, says multibillionaire Sam Altman. So we bear the risks and he keeps the money | Chris Stokel-Walker

    October 7, 2026
    Latest Posts

    4 Best Compression Boots: Therabody, Hyperice, and More (2026)

    August 9, 2026

    Former Iraqi provincial governor arrested as graft crackdown continues | Corruption News

    August 9, 2026

    The culture surrounding ‘ideal’ childbirth has to evolve | Childbirth

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

    October 7, 2026

    Someone Scraped 5.6 Billion TikTok Videos and Put the Data on Hugging Face for Free

    October 7, 2026

    Physicists just saw quarks make waves in the Big Bang’s primordial soup

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.