Google report: vulnerability disclosures doubled in eight months as AI shifts what gets found
AI agents are changing which vulnerabilities get discovered, but raw totals are inflated by automated identifiers; patching priorities need threat intelligence.
Google's Threat Intelligence Group reported on September 30 that monthly vulnerability disclosures grew from 5,045 in January to 10,740 in August, doubling in eight months.
The report estimates that about half of the vulnerabilities found by AI agents allow remote code execution, against 26% of all disclosures. It also cautions that automated identifier assignment in open-source ecosystems inflates raw totals: records mentioning "Linux Kernel" numbered about 5,000 this year without producing a single zero-day exploited in the wild.
The exploitation signal is firmer: attackers exploited 141 newly disclosed vulnerabilities in the wild from January to August, already more than the 127 recorded across all of 2025. GTIG advises organizations to drop unprioritized mass patching and let threat intelligence decide what gets fixed first.
Sources:https://cloud.google.com/blog/topics/vulnerability-discovery-and-exploitation-trends-in-the-ai-erahttps://siliconangle.com/2026/09/30/google-finds-vulnerability-disclosures-doubled-as-ai-changes-which-flaws-get-discovered