Google AI Identifies More Medium-Risk Vulnerabilities, Attackers Focus on N-Days
Google's analysis shows AI is finding more medium-risk software flaws, while attackers increasingly exploit known, unpatched vulnerabilities (N-days) over zero-days.

Artificial intelligence is increasingly being employed to discover software vulnerabilities, but Google's recent analysis indicates that these AI-driven findings are predominantly medium-risk, rather than the high-risk flaws that might trigger widespread panic. Over an 18-month period, Google researchers observed that AI tools are identifying a growing number of vulnerabilities, contributing to a doubling of known flaws to over 10,000. However, the distribution of risk associated with these AI-discovered bugs leans towards the moderate end of the spectrum.
This trend suggests that current AI applications in vulnerability research are either being directed towards broader system scans that naturally uncover more minor issues, or that the AI models themselves are more adept at finding less critical bugs. While the feared "vulnpocalypse" driven by AI hasn't materialized in the form of a massive surge in critical zero-day exploits, the sheer volume of disclosed vulnerabilities still necessitates a robust defense strategy. Google emphasizes that organizations must adapt their approach to vulnerability management to handle this escalating number of CVEs.
Kellie Vanderlee, a senior analyst at Google Threat Intelligence Group, advised that enterprises need to modernize their processes for triaging and remediating disclosed exploits. This includes having efficient patch management plans and maintaining an accurate understanding of their asset inventory, including their exposure to the internet. Continuous testing of this understanding is crucial to ensure that defenses align with the actual attack surface.
Meanwhile, threat actors are reportedly accelerating their exploitation of "N-day" vulnerabilities – flaws that have been publicly disclosed but not yet patched by all affected parties. This strategy is often more effective than expending resources on discovering elusive zero-days, as N-days offer a more immediate and accessible attack vector. Threat actors are likely leveraging AI to automate the analysis of differences between software versions, patches, and vulnerability disclosures, thereby speeding up the weaponization of these known weaknesses.
Google's research also delved into the security of AI infrastructure itself, identifying 782 vulnerabilities within AI orchestration and agent frameworks out of 1,500 total flaws found. Systems utilizing popular frameworks like LangChain, LlamaIndex, and Autogen were among those found to be vulnerable. Frontier AI models from major providers like Anthropic, Google, and OpenAI also accounted for a notable number of vulnerabilities.
Attackers are exploiting these orchestration frameworks through techniques such as prompt injection, which can hijack execution loops and transform natural language prompts into channels for remote code execution. Furthermore, centralized AI gateways, which enterprises use to manage model routing and API keys, present another significant security risk. These gateways can act as initial footholds for attackers to harvest database credentials and expose sensitive data, including API keys and proprietary source code.
While the data on AI-assisted vulnerability discovery and its associated threats is still nascent, the early indicators suggest it will become a substantial component of future threat analysis. Security researchers and AI companies are actively promoting the use of AI agents for defensive purposes, aiming to provide defenders with an advantage over rapidly evolving threat actors. However, the findings also highlight the critical need to secure the AI infrastructure itself, as it becomes an increasingly attractive target for exploitation.