Volver a Noticias
SeguridadAI Understanding sesión informativa

Los agentes de IA duplican la tasa de hallazgos de ejecución remota de código y aceleran los cronogramas de explotación

Un nuevo informe de GTIG muestra que agentes de investigación autónomos están descubriendo fallas de RCE en el 50% de los escaneos (casi el doble del promedio de la industria) y los actores de amenazas los están utilizando como armas en cuestión de días.

4 min readRead the linked source
Source-provided image accompanying AI agents double rate of remote code execution findings and accelerate exploit timelines
Referencia fuenteFuente registrada
Editor
forkast.news
Enlace fuente
forkast.newshttps://forkast.news/ai-agents-find-rce-vulnerabilities-at-double-the-traditional-rate-and-attackers-exploit-them-in-days/
Tipo de fuente
Fuente vinculada: no se ha establecido el estado de fuente primaria.
ContextoEntiende esto en 60 segundos

Empieza aquí

Términos clave

Modelo de lenguaje grande (LLM)
Un modelo de lenguaje entrenado en corpus de texto masivos para generar y analizar texto.
Ponte a pruebaPrueba de agentes de IA

que paso

Autonomous research agents identified remote code execution (RCE) vulnerabilities at a 50% discovery rate, nearly double the 26% rate seen across the broader CVE ecosystem, according to the GTIG report released September 30, 2026. The report highlights the rapid weaponization of a high‑severity flaw (CVE‑2026‑1731) in BeyondTrust remote support software, which was discovered by Hacktron AI on January 31, 2026 and exploited by multiple threat clusters within a week. Monthly vulnerability disclosures rose from 5,045 in January 2026 to 10,740 in August 2026, with high‑risk findings increasing 167%. AI‑discovered flaws skew toward medium and high risk, and the AI/LLM software stack itself saw a 347% surge in CVEs, driven largely by agent orchestration frameworks.

The GTIG (Global Threat Intelligence Group) report, compiled from telemetry of multiple security platforms, measured the performance of autonomous research agents that scan enterprise software for vulnerability classes and variants. These agents achieved a 50% success rate in surfacing RCE bugs, compared with a 26% baseline for the broader CVE ecosystem.

A concrete example is CVE‑2026‑1731, a pre‑authentication RCE in BeyondTrust remote support. Hacktron AI’s variant‑analysis engine flagged the flaw on Jan 31, 2026. Within four days, threat actors began exploiting it, and by day seven five distinct threat clusters were deploying ransomware‑type payloads such as SparkRAT and VShell, and exfiltrating data via DNS tunneling. Cortex Xpanse telemetry recorded over 16,400 exposed instances across multiple continents.

The report also documents a macro trend: monthly disclosed vulnerabilities doubled between Jan and Aug 2026, while high‑risk disclosures rose 167%. AI‑found vulnerabilities are disproportionately medium‑risk (58%) and high‑risk (4%), whereas conventional methods still produce mostly low‑risk findings (69%).

AI‑related software itself is increasingly vulnerable. From Jan 2025 to Aug 2026, 2,076 CVEs were logged in the AI/LLM stack, with 1,500 occurring in the first eight months of 2026. Agent orchestration frameworks contributed 782 CVEs (≈50% of AI‑related flaws) and saw a 347% increase year‑over‑year. Specific examples include CVE‑2026‑42271 in LiteLLM and CVE‑2026‑5027 in Langflow.

Detalles de la fuente: forkast.news ↗

Por qué es importante

The acceleration of AI‑driven vulnerability discovery compresses the window between flaw identification and exploitation to days, outpacing traditional patch‑management cycles. Enterprises across finance, healthcare, and government now face a structural security gap: AI agents can surface complex code‑path bugs that human analysts miss, while adversaries quickly repurpose the same findings for ransomware, backdoors, and data exfiltration. The report also reveals that the AI infrastructure—agent orchestration tools, LLM runtimes, and related libraries—has become a prolific attack surface, accounting for half of AI‑related CVEs in 2026. This dual‑use dynamic amplifies supply‑chain risk and forces security teams to rethink detection, attribution, and remediation strategies.

The compressed discovery‑to‑exploit timeline erodes the effectiveness of traditional vulnerability‑management lifecycles, which often assume weeks or months to develop, test, and deploy patches.

Enterprise risk exposure expands beyond the original software vendor; compromised AI orchestration tools can cascade across downstream services, magnifying supply‑chain threats.

Regulators and industry groups may need to mandate faster disclosure windows or require vendors to integrate AI‑driven detection into their security product roadmaps.

The shift in risk distribution—more medium and high‑severity findings from AI agents—means security teams must prioritize triage differently, potentially allocating more resources to AI‑generated alerts.

Interactive Mechanism

Mecanismo interactivo: cómo funciona realmente

Explore la tecnología subyacente detrás de este desarrollo de forma interactiva.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Verificación interactiva del concepto+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

Qué ver a continuación

Watch for: (1) vendor‑level responses such as faster coordinated disclosure processes and automated patch delivery; (2) emergence of AI‑specific threat‑intel feeds that track agent‑generated exploits; (3) regulatory or industry standards addressing AI‑augmented vulnerability research; and (4) development of defensive AI agents designed to prioritize high‑impact findings and auto‑mitigate exploits before they spread.

Vendor initiatives: Look for announcements from major security vendors (e.g., Microsoft, Palo Alto, Tenable) about automated patch‑delivery or AI‑enhanced remediation workflows.

Threat‑intel evolution: Expect new feeds that specifically tag AI‑generated exploits, enabling SOCs to correlate alerts faster.

Policy developments: Track proposals from standards bodies (e.g., ISO/IEC, NIST) that address AI‑augmented vulnerability research and responsible disclosure.

Defensive AI agents: Monitor startups and research labs building AI systems that can not only discover but also automatically contain or neutralize high‑risk flaws before they are weaponized.

Guías y cuestionarios relacionados

Agentes de IAÉtica de la IAFuturo de la IAPon a prueba lo que sabes: prueba un cuestionario gratuito sobre IABusque un término de IA en nuestro glosarioSiga el rastreador de regulaciones de IA
¿Encontró esto útil?