AI-era vulnerability defence needs an exposure-led queue that links discovery speed to exploit evidence and accountable remediation
Source: Google Cloud
Google Threat Intelligence Group examined disclosure and in-the-wild exploitation from January 2025 through August 2026 and says artificial intelligence is changing both the pace and the risk profile of discovered vulnerabilities. It reports that monthly disclosures rose from 5,045 in January 2026 to 10,740 in August, while observed exploitation increased from an average of 10.5 vulnerabilities a month in 2025 to 18 a month in 2026. The report also notes that only about 0.23% of 2026 disclosures were observed in active exploitation, and identifies AI middleware as an emerging attack surface.
Why this matters: A larger discovery stream is not a reason to patch blindly. Join the incoming intelligence to an owned asset inventory, internet exposure, exploit activity, reachable paths, business criticality, and existing mitigations; use that evidence to set a remediation target and an accountable approver. For AI platforms, include the agent runtime, model gateway, MCP and tool endpoints, secrets, and compute controls in that inventory. Automate enrichment and containment where it is safe, but preserve a tested exception and rollback path for production changes.
Read Google Threat Intelligence Group's vulnerability-trends analysis