CyberSecurity SEE

AI Accelerates N-Day Attacks as Flaw Disclosures and Exploits Increase

AI Accelerates N-Day Attacks as Flaw Disclosures and Exploits Increase

Increasing Exploitation of Disclosed Vulnerabilities Raises Alarms in Cybersecurity

In recent months, cybersecurity experts have observed a troubling shift in the tactics employed by cybercriminals. Rather than exclusively seeking out new exploits, attackers are increasingly weaponizing already-disclosed vulnerabilities, accelerating the pace of exploitation due to advancements in artificial intelligence (AI) tools. This alarming trend has been highlighted in a report released by Google’s Threat Intelligence Group (GTIG), which outlines the significant rise in the number of vulnerabilities exploited in the wild this year.

Between January and August of 2026, GTIG recorded a staggering 141 flaws exploited, surpassing the total of 127 vulnerabilities that were exploited throughout all of 2025. This data reflects a broader trend, with the average monthly vulnerability disclosures soaring. In January alone, there were 5,045 new flaws reported, which surged to 10,740 by August. This unprecedented increase has led to a corresponding rise in exploitation rates, with figures jumping from an average of 10.5 exploitations per month last year to nearly 18 in 2026. In contrast, the exploitation of zero-day vulnerabilities has seen a modest rise, from 8 to 11 per month, painting a clear picture of a shifting threat landscape.

This evolving dynamic is reinforced by findings from Foundry’s upcoming Security Priorities survey, revealing that security leaders are expressing greater concern over “n-days” — previously disclosed vulnerabilities — than zero-days. In the survey, 38% of respondents indicated heightened concern regarding software n-day exploitation, while 37% were focused on network n-day threats. Comparatively, only 25% showed concern for zero-day exploits.

GTIG researchers suggest that the accessibility and efficiency of AI tools, particularly large language models (LLMs), are enabling threat actors to automate the analysis of differences across product versions and vulnerabilities. By utilizing these tools, attackers can rapidly weaponize n-days instead of hunting for new zero-days, which may be a more labor-intensive endeavor. The implications of this are profound, as it signifies a shift in focus from discovering unknown vulnerabilities to exploiting those already made public.

Additionally, the nature of the vulnerabilities targeted by attackers has shifted significantly. The report notes a troubling increase in the exploitation of high-risk flaws, with incidents rising from 28 in 2025 to 75 in the first eight months of 2026. This increase corresponds with a spike in the disclosure of critical vulnerabilities, which has risen from 131 in January to 350 by August.

Steve Povolny, the vice president of AI strategy and security research at Exabeam, commented on this alarming trend, stating, “While this is of course concerning, it’s hardly unexpected. We know by now that AI models can achieve speed, scale, and efficiency that few, if any, human beings are capable of.” This rapid scalability of AI in vulnerability exploitation underscores the urgency with which companies must act to safeguard their digital assets.

One notable aspect highlighted in the GTIG report is the doubling of the number of new Common Vulnerabilities and Exposures (CVEs) reported. The report warns, however, that automated CVE Numbering Authority assignments across open-source ecosystems may be artificially inflating these numbers. Illustrating this point, vulnerabilities associated with the Linux kernel alone accounted for roughly 5,000 CVEs in the first eight months of the year, despite an absence of zero-days exploited in the wild.

Moreover, significant spikes in high-risk flaws have been noted from specific vendors. For instance, Totolink addressed 75 high-risk flaws in its consumer router firmware between April and May, leading to a mid-year surge in command execution vulnerabilities. Similarly, Oracle’s quarterly Critical Patch Update revealed 128 high-risk vulnerabilities in August across its middleware products.

What remains concerning is that despite the high volume of vulnerability disclosures, the exploitation of these disclosed flaws represents only a small fraction—approximately 0.23% or around 1 in 431 vulnerabilities. Trends indicate that although exploitation activity is rising, it does not necessarily outpace the growth of vulnerability disclosures.

Interestingly, data from vulnerability intelligence firm VulnCheck confirms a decline in the ratio of exploited to disclosed vulnerabilities, which dropped to 1.4% in the first half of 2026 from a peak of 2.7% in 2023. This emphasizes that the rate of vulnerability disclosure is growing at a far more rapid pace than actual exploitation incidents. The observed median time from a CVE’s publication to confirmation of its exploitation also decreased, falling from 120 days in 2025 to 80 days in early 2026, potentially illustrating the effect of AI in ongoing attacks.

The areas targeted by attackers reveal a concentrated focus on network-edge and security appliances, which accounted for 14% of exploited vulnerabilities from January to August, with two-thirds of these flaws bearing high or critical severity ratings. Attackers have been particularly drawn to unauthenticated public management interfaces, as these systems can often evade detection by enterprise endpoint security measures.

In light of these trends, cybersecurity experts assert that companies must adopt more strategic approaches to vulnerability management. Detectify, a firm that assesses customer exposure to external threats, found that critical and high-severity flaws in internet-facing assets often remain unaddressed for over 90 days. This highlights a worrying disconnect, as organizations grapple with increasing exposure even before existing vulnerabilities are mitigated.

The Cybersecurity and Infrastructure Security Agency (CISA) recently published a new framework aimed at enhancing the quality of the CVE program, responding to the alarming number of newly published CVEs expected to approach 100,000 by year-end 2026. However, experts, including Farzad Bakhtiar from Flashpoint, caution that a well-documented vulnerability does not necessarily translate into actionable intelligence.

In summary, as the landscape of cybersecurity continues to evolve, the implications of AI in the exploitation of disclosed vulnerabilities signal a pressing need for organizations to refine their vulnerability management strategies. By leveraging intelligence and adopting proactive remediation measures, companies can better shield themselves from the increasingly sophisticated tactics employed by cyber adversaries.

Source link

Exit mobile version