A Google report shows that artificial intelligence is changing the landscape of cybersecurity: it is not secret breaches that pose the main threat to a small business, but rather the speed at which a fix becomes an attack.
Google's Threat Intelligence Group (GTIG) analyzed how attackers are using artificial intelligence. The main finding isn't spectacular, but it is important: the number of publicly disclosed vulnerabilities has doubled in eight months, and attackers are using AI primarily to quickly turn an already patched vulnerability into a working attack—not so much to discover new, hidden vulnerabilities.
This changes the equation for a small business. The window between when a vulnerability is discovered and when it is already being exploited in attacks has shrunk from weeks to days. A vulnerability in a well-known security product, BeyondTrust, was exploited within four days of the patch’s release; five other attack groups followed within seven days.
Furthermore, vulnerabilities discovered using AI are more dangerous: half of them allow remote code execution—the most serious type of vulnerability—compared to about a quarter of those found using traditional methods.
For a company without an IT department, the message isn't "buy more technology," but "don't put off the simple things." The habit of putting off updates has actually become a risk.
What you need to do:
- Enable automatic updates wherever possible: Windows, browsers, phones.
- Quickly apply critical updates to anything exposed to the internet—routers and firewalls, hosting control panels, VPNs, and remote access tools. That’s where code-execution attacks strike.
- If you work with a maintenance company, ask what their timeline is for applying updates to edge devices and request it in writing.
Sources: Help Net Security | https://www.helpnetsecurity.com/2026/10/01/google-ai-discovered-vulnerabilities-remote-code-execution/
This article was generated with AI assistance.