'It is possible that threat actors are finding it more accessible or efficient to use LLMs and AI tools': Google warns that AI explosion will lead to more dangerous and advanced security threats
It's not about zero-days, at all, but rather about properly exploiting already known flaws, Google says.
Recent analysis by Google's Threat Intelligence Group (GTIG) suggests that the use of AI and large language models (LLMs) is making it easier for cybercriminals to quickly exploit known software vulnerabilities. The report reveals a notable surge in discovered flaws and their real-world exploitation, with AI accelerating this process.
However, contrary to expectations, the focus isn't on discovering new zero-day vulnerabilities, but rather on rapidly weaponizing known flaws. While AI has helped cybercriminals find and exploit software bugs more efficiently, it's also enabling defenders to prioritize security based on threat intelligence. AI is being primarily used to discover vulnerabilities in critical infrastructure, privilege boundaries, core libraries, and runtime environments.
A notable example of this is CVE-2026-1731, a command-injection vulnerability in BeyondTrust products, which threat actors exploited within days of its public disclosure. As AI and LLMs continue to evolve, both vulnerability discovery and exploitation rates are expected to increase. In response, organizations need to adopt intelligence-led patching and move away from broad, unprioritized patching programs, instead focusing on threat-intelligence-driven vulnerability management to keep pace with rapidly evolving automated adversaries.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.