Exploitation Is Rising Faster Than Zero-Days as Attackers Accelerate N-Day Weaponization
A sharp uptick in artificial intelligence-spotted vulnerabilities so far hasn’t resulted in a corresponding explosion in hacking, Google says. AI is mostly identifying medium-risk flaws, the computing giant found in an analysis of disclosed vulnerabilities made over the past 18 months.
See Also: What If Your OT Perimeter Looks Secure – but the Threat Is Already Inside?
Security groups feared that AI would drive a “vulnpocalypse” of new flaws vastly outpacing defenders’ ability to patch them. And to some extent, it is happening, with the number of known flaws doubling over the past 18 months, reaching more than 10,000 in July this year.
But when Google investigated AI’s ability to discover “more consequential vulnerabilities,” it found that the tools more often lead to medium-risk vulnerabilities rather than low- or high-risk bugs. Google researchers said the trend reflects how AI is being used. Vulnerability researchers tend to aim AI tools at critical systems in the hopes of finding a serious flaw rather than doing broad system scans – which would likely find more minor issues.
Of all the vulnerabilities discovered with AI that were recognized with a common vulnerabilities and exposures tracking number from January to August this year, 58% were medium risk. Only 4% were of high risk, roughly the same percentage of high-risk vulnerabilities discovered without AI.
Google said enterprises should nonetheless modify their defense strategy to account for the surging number of CVEs. Kellie Vanderlee, senior analyst at Google Threat Intelligence Group, told ISMG in an email that organizations must modernize how they triage and remediate any disclosed exploit.
“Organizations should have an efficient patch management plan as well as ensure that they have an accurate understanding of their assets and their accessibility to the internet and test that understanding,” she said.
Threat actors themselves likely use AI to “automate analysis of differences between product versions, patches, vulnerability disclosure announcements” and more effectively weaponize n-days. Quickly using newly disclosed, but still not fully patched, flaws is often more effective a hacking technique than attempting to discover a zero-day, of which there has been only a marginal increase in quantity.
Google also investigated which parts of the AI infrastructure stack are most vulnerable to attackers. The researchers identified 782 vulnerabilities in AI orchestration and agent frameworks out of the 1,500 vulnerabilities they found overall. These include systems that run on LangChain, LlamaIndex, Autogen, CrewAI and MCP, among others. Frontier models from Anthropic, Google and OpenAI accounted for 97 vulnerabilities.
Google said attackers exploit orchestration frameworks through prompt injection to hijack execution loops, turning natural language prompts into remote-code execution channels.
Another potential infrastructure security flaw is centralized AI gateways, a growing avenue for enterprises to offload model routing, API keys and usage limits without connecting directly to model providers. Google said these act as “initial footholds” to harvest database credentials.
“Enterprise AI gateways represent a catastrophic dual-threat vector. At the application layer, compromised gateways expose third-party API keys and private prompt streams containing personally identifiable information or proprietary source code,” the report said.
Google researchers said these are still early days for gathering publicly available data on AI-assisted discovery and threats. Still, signs already point to that becoming a large part of threat analysis in the future.
Many security researchers and AI companies have been pushing organizations to shore up their defenses by turning to AI agents. OpenAI President Greg Brockman said in an essay that defenders have a shorter window to protect themselves, and security-focused AI agents will give them an advantage over threat actors.
Click Here For The Original Source.
