CompaniesInvestorsPeople
Home
Loading

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

aVenture is in Beta: research coverage is expanding as we build, so please independently verify key details before making investment decisions.

Get in Touch

  • Contact

  • Request a Demo

  • Request Data Updates

  • Add a Company

Research

  • Companies

  • Investors

  • People

aVenture

  • Download App

  • Pricing

Download the aVenture Research beta for iOS and iPadOSDownload aVenture Research on the Mac App Store

Resources

  • Documentation

  • CLI

  • MCP

  • Feature Requests

  • Sitemap

Member

Backed by

© aVenture Investment Company, 2026. All rights reserved.

San Francisco, CA, USA

Privacy Policy · Terms of Service

aVenture Investment Company ("aVenture") is an independent research platform providing detailed analysis and data on startups, venture capital investments, and key industry individuals. It is not a registered investment adviser, broker-dealer, or investment advisor and does not provide investment advice or recommendations. The data provided by aVenture does not constitute recommendations or advice, whether by methodology, analysis, AI-generated content, or a statement written by a staff member of aVenture.

aVenture is not affiliated with any of the people, companies, organizations, government agencies, regulatory bodies, or investment funds we provide coverage for on this site unless explicitly stated otherwise. Users assume full responsibility for decisions made based on information obtained from this platform. Links to external websites do not imply endorsement or affiliation with aVenture. Any links that provide the ability to invest in a primary or secondary transaction in a company are for convenience only and do not constitute solicitations or offers to buy or sell an investment. Investors should exercise heightened precaution and due diligence when investing in private companies, especially those not independently audited.

While we strive to provide valuable insights with objectivity and professional diligence, we cannot guarantee the accuracy of the information provided on our platform. Before making any investment decisions, you should verify the accuracy of all pertinent details for your decision. To the fullest extent permitted by law, aVenture shall not be liable for any direct, indirect, incidental, consequential, or financial damages arising from use of this site, whether by consumers of its contents directly or by persons or organizations covered by our research, even if we are advised of the possibility. Our best-efforts processes and correction request forms do not create a warranty or duty of care.

Profiles on this platform may include content generated in part by large language models (LLMs, artificial intelligence) that aggregate publicly available sources (e.g., SEC EDGAR, public filings, press releases). Source attribution is provided where known; always verify statements and claims here against original sources before relying on any data. Content on our site may contain inaccuracies, omissions, or what are commonly called 'hallucinations' if generated in part or in full by AI / LLMs. The risk can also exist even when content is written by a human, as internal and third-party sources may also have inaccuracies for the same or different reasons. While we randomly audit a proportion of content, this is not exhaustive.

We recommend that an independent auditor be hired to verify the accuracy of the information before relying on it for any sensitive decisions. By accessing this platform, you agree not to rely solely on any information generated by AI, aggregated, or sourced or written otherwise on this site, for investment, financial, or other decisions. aVenture assumes no responsibility for inaccuracies, omissions, or hallucinations. You must independently verify all data from primary sources. Use of this platform constitutes your waiver of claims for reliance-based damages, including negligent misrepresentation. To report an error, request a correction, or dispute information about a company or individual, contact us via our request data updates form.

Loading
Loading
Home
News
Google finds vulnerability disclosures doubled as AI changes which flaws get discovered

From SiliconAngle

By Duncan Riley

September 30, 2026

Google finds vulnerability disclosures doubled as AI changes which flaws get discovered

Google finds vulnerability disclosures doubled as AI changes which flaws get discovered

A new report out today from Google LLC’s Google Threat Intelligence Group finds that monthly software vulnerability disclosures doubled between January and August.

Not surprisingly, artificial intelligence is changing which flaws get discovered as well, and GTIG said half of those turned up by AI agents allow remote code execution.

August’s count of 10,740 vulnerability disclosures was more than twice January’s 5,045. GTIG cautioned that raw totals can overstate the threat, because automated identifier assignment in open-source ecosystems inflates them. Flaws with “Linux Kernel” in their descriptions accounted for about 5,000 records this year without producing a single zero-day exploited in the wild. High-risk disclosures on GTIG’s own scale rose 167% over the same months to 350 in August, and 128 of those came from Oracle Corp.’s quarterly patch release and Linux kernel network driver advisories.

By GTIG’s count, attackers exploited 141 newly disclosed vulnerabilities in the wild between January and August, more than the 127 recorded across all of 2025. Measured against disclosure volume the number is small, at about one flaw in 431, and the report notes that a single vendor’s disclosure cycle or one busy campaign can move the monthly figure.

Zero-day exploitation has averaged 11 a month so far this year against eight in 2025, with most months landing between eight and 12 until August brought 22. Zero-days, new vulnerabilities that haven’t been patched, still made up 62% of the 141 exploited flaws. Most of the growth, GTIG suggests, has come from n-days, meaning flaws that attackers go after once they are public and usually already patched.

Attackers may be using large language models to compare product versions and patches, the report says, so they can turn known flaws into working exploits quickly. Exploited high-risk flaws numbered 75 this year, up from 28 in all of 2025.

The report then turns to the vulnerabilities AI itself is finding. GTIG believes public data undercounts them, since vulnerability databases carry no standard tag for AI-assisted discovery. Large cloud and software-as-a-service providers also fix many AI-surfaced bugs in production without ever requesting an identifier, because those identifiers are normally reserved for software that customers have to patch themselves.

Among the vulnerabilities GTIG identified as likely AI discoveries, 58% fell in the moderate tier of its risk scale. Bugs found by people and conventional scanners land there about half as often, and 69% of those rate as low-risk. Researchers tend to aim their agents at critical infrastructure and sensitive privilege boundaries on purpose, and GTIG thinks that choice likely explains much of the gap.

Remote code execution shows up in only 26% of all other disclosures, and the report says AI’s higher rate likely stems from how well agents pick out memory corruption and logic bypasses deep in C and C++ code that static analyzers tend to miss.

GTIG treats confirmed attacks on AI-found flaws as an early indicator for now. The example it cites to show the risk is “not purely theoretical” is CVE-2026-1731. The bug lets an unauthenticated attacker inject operating system commands into BeyondTrust Corp.’s Privileged Remote Access and Remote Support products, and a research agent from Hacktron AI Inc. found it autonomously.

Within four days of disclosure in February, GTIG saw one threat cluster exploiting the flaw, and five more had joined within a week. The attackers went on to escalate privileges and steal data, and payloads they dropped included SNOWLIGHT and SPARKRAT malware plus cryptocurrency miners.

The report’s final section covers flaws in AI software. Of the 2,076 such disclosures GTIG has tracked since the start of 2025, more than 1,500 came this year. Agent orchestration frameworks such as Flowise and Langflow account for roughly half.

Visual workflow builders of that kind often include nodes that execute code, and attackers can reach them with prompt injection or a crafted workflow file. Inference and serving software such as vLLM, Ollama and LiteLLM drew 212 disclosures, and GTIG traced nearly a quarter of them to unauthenticated application programming interface endpoints or server-side request forgery.

GTIG has not yet observed zero-day exploitation of AI infrastructure. Only a handful of disclosed flaws have been exploited in the wild, among them a command injection bug in LiteLLM’s Model Context Protocol server preview endpoints and two in Langflow. In July, Sysdig Inc. documented an autonomous ransomware attack that broke in through the older of the Langflow flaws.

The Google unit expects discovery and exploitation to keep climbing over the short to medium term. Exploitation remains concentrated on perimeter appliances and exposed enterprise services, according to the report.

Its advice to organizations is to drop unprioritized mass patching and let threat intelligence decide what gets fixed first, with targeted defenses at the edge. Software vendors should run agentic AI code review before code ships, the report argues, naming Google’s own CodeMender as one option. If that becomes standard practice, growth in public disclosures could eventually slow, GTIG said.

View original article on siliconangle.com

Most Recent

Factory CEO just accused his VC board advisor of spying for Cognition

VC Chris Degnan and former board advisor to Factory AI has taken a job as chief revenue officer for Cognition.

Sep 30, 2026

CEO George Kurian outlines NetApp’s data strategy for production AI

NetApp’s Novus combines performance, governance and security as intelligent data infrastructure supports the shift to production AI.

Sep 30, 2026

Apollo debuts AI app builder, intelligence layer and signal-based outreach system

Sales software company Apollo today unveiled a set of artificial intelligence products designed to move more of a revenue team’s daily work onto one platform. The launch goes after a problem Apollo describes as tool sprawl. Most sales organizations assembled their software one product at a time, oft

Sep 30, 2026

AWS embeds DuckDB in its PostgreSQL DBMS to speed queries of live and historical data

Amazon Web Services Inc. is adding the ability to query the popular Apache Iceberg data lake directly from its Aurora PostgreSQL database management system, allowing applications to combine live transactions with historical records without copying data or creating extract/transform/load pipelines. T

Sep 30, 2026

Similar Posts

Google warns of new Chrome zero-day flaw exploited in attacks

Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities.

Sep 4, 2026

An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang

TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.

Sep 18, 2026

Nvidia NemoClaw flaw let attackers poison the model behind a developer’s AI agent

Nvidia NemoClaw flaw let attackers poison the model behind a developer's AI agent - SiliconANGLE

Aug 25, 2026

Google says attackers used AI agents to steal credentials in under six hours

Threat actors used a multi-agent artificial intelligence framework to compromise thousands of credentials in under six hours, Google LLC’s Google Threat Intelligence Group said in a report released today. Mandiant investigators traced the campaign to a suspected financially motivated actor that firs

Sep 8, 2026