accelerate-exploitation

A Google report shows that artificial intelligence is changing the landscape of cybersecurity: it is not secret breaches that pose the main threat to a small business, but rather the speed at which a fix becomes an attack.

Google's Threat Intelligence Group (GTIG) analyzed how attackers are using artificial intelligence. The main finding isn't spectacular, but it is important: the number of publicly disclosed vulnerabilities has doubled in eight months, and attackers are using AI primarily to quickly turn an already patched vulnerability into a working attack—not so much to discover new, hidden vulnerabilities.

This changes the equation for a small business. The window between when a vulnerability is discovered and when it is already being exploited in attacks has shrunk from weeks to days. A vulnerability in a well-known security product, BeyondTrust, was exploited within four days of the patch’s release; five other attack groups followed within seven days.

Furthermore, vulnerabilities discovered using AI are more dangerous: half of them allow remote code execution—the most serious type of vulnerability—compared to about a quarter of those found using traditional methods.

For a company without an IT department, the message isn't "buy more technology," but "don't put off the simple things." The habit of putting off updates has actually become a risk.

What you need to do:

  • Enable automatic updates wherever possible: Windows, browsers, phones.
  • Quickly apply critical updates to anything exposed to the internet—routers and firewalls, hosting control panels, VPNs, and remote access tools. That’s where code-execution attacks strike.
  • If you work with a maintenance company, ask what their timeline is for applying updates to edge devices and request it in writing.

Sources: Help Net Security | https://www.helpnetsecurity.com/2026/10/01/google-ai-discovered-vulnerabilities-remote-code-execution/

This article was generated with AI assistance.

Request a quote

← All news