Înapoi la Știri
SecuritateAI Understanding briefing

Agenții AI dublează rata de execuție a codului de la distanță și accelerează termenele de exploatare

Un nou raport GTIG arată că agenții de cercetare autonomi descoperă defecte RCE la 50% din scanări - aproape de două ori media industriei - și actorii amenințărilor le armează în câteva zile.

4 min readRead the linked source
Source-provided image accompanying AI agents double rate of remote code execution findings and accelerate exploit timelines
Referință la sursăSursa înregistrată
Editor
forkast.news
Link sursă
forkast.newshttps://forkast.news/ai-agents-find-rce-vulnerabilities-at-double-the-traditional-rate-and-attackers-exploit-them-in-days/
Tip sursă
Sursă conectată — starea sursei primare nu a fost stabilită.
ContextÎnțelege asta în 60 de secunde

Începeți de aici

Termeni cheie

Model de limbă mare (LLM)
Un model de limbaj instruit pe corpuri de text masive pentru a genera și analiza text.
Testează-teTest pentru agenții AI

Ce sa întâmplat

Autonomous research agents identified remote code execution (RCE) vulnerabilities at a 50% discovery rate, nearly double the 26% rate seen across the broader CVE ecosystem, according to the GTIG report released September 30, 2026. The report highlights the rapid weaponization of a high‑severity flaw (CVE‑2026‑1731) in BeyondTrust remote support software, which was discovered by Hacktron AI on January 31, 2026 and exploited by multiple threat clusters within a week. Monthly vulnerability disclosures rose from 5,045 in January 2026 to 10,740 in August 2026, with high‑risk findings increasing 167%. AI‑discovered flaws skew toward medium and high risk, and the AI/LLM software stack itself saw a 347% surge in CVEs, driven largely by agent orchestration frameworks.

The GTIG (Global Threat Intelligence Group) report, compiled from telemetry of multiple security platforms, measured the performance of autonomous research agents that scan enterprise software for vulnerability classes and variants. These agents achieved a 50% success rate in surfacing RCE bugs, compared with a 26% baseline for the broader CVE ecosystem.

A concrete example is CVE‑2026‑1731, a pre‑authentication RCE in BeyondTrust remote support. Hacktron AI’s variant‑analysis engine flagged the flaw on Jan 31, 2026. Within four days, threat actors began exploiting it, and by day seven five distinct threat clusters were deploying ransomware‑type payloads such as SparkRAT and VShell, and exfiltrating data via DNS tunneling. Cortex Xpanse telemetry recorded over 16,400 exposed instances across multiple continents.

The report also documents a macro trend: monthly disclosed vulnerabilities doubled between Jan and Aug 2026, while high‑risk disclosures rose 167%. AI‑found vulnerabilities are disproportionately medium‑risk (58%) and high‑risk (4%), whereas conventional methods still produce mostly low‑risk findings (69%).

AI‑related software itself is increasingly vulnerable. From Jan 2025 to Aug 2026, 2,076 CVEs were logged in the AI/LLM stack, with 1,500 occurring in the first eight months of 2026. Agent orchestration frameworks contributed 782 CVEs (≈50% of AI‑related flaws) and saw a 347% increase year‑over‑year. Specific examples include CVE‑2026‑42271 in LiteLLM and CVE‑2026‑5027 in Langflow.

Detalii sursa: forkast.news ↗

De ce contează

The acceleration of AI‑driven vulnerability discovery compresses the window between flaw identification and exploitation to days, outpacing traditional patch‑management cycles. Enterprises across finance, healthcare, and government now face a structural security gap: AI agents can surface complex code‑path bugs that human analysts miss, while adversaries quickly repurpose the same findings for ransomware, backdoors, and data exfiltration. The report also reveals that the AI infrastructure—agent orchestration tools, LLM runtimes, and related libraries—has become a prolific attack surface, accounting for half of AI‑related CVEs in 2026. This dual‑use dynamic amplifies supply‑chain risk and forces security teams to rethink detection, attribution, and remediation strategies.

The compressed discovery‑to‑exploit timeline erodes the effectiveness of traditional vulnerability‑management lifecycles, which often assume weeks or months to develop, test, and deploy patches.

Enterprise risk exposure expands beyond the original software vendor; compromised AI orchestration tools can cascade across downstream services, magnifying supply‑chain threats.

Regulators and industry groups may need to mandate faster disclosure windows or require vendors to integrate AI‑driven detection into their security product roadmaps.

The shift in risk distribution—more medium and high‑severity findings from AI agents—means security teams must prioritize triage differently, potentially allocating more resources to AI‑generated alerts.

Interactive Mechanism

Mecanism interactiv: cum funcționează de fapt

Explorați tehnologia care stau la baza acestei dezvoltări în mod interactiv.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Verificare interactivă a conceptului+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

Ce să urmărești în continuare

Watch for: (1) vendor‑level responses such as faster coordinated disclosure processes and automated patch delivery; (2) emergence of AI‑specific threat‑intel feeds that track agent‑generated exploits; (3) regulatory or industry standards addressing AI‑augmented vulnerability research; and (4) development of defensive AI agents designed to prioritize high‑impact findings and auto‑mitigate exploits before they spread.

Vendor initiatives: Look for announcements from major security vendors (e.g., Microsoft, Palo Alto, Tenable) about automated patch‑delivery or AI‑enhanced remediation workflows.

Threat‑intel evolution: Expect new feeds that specifically tag AI‑generated exploits, enabling SOCs to correlate alerts faster.

Policy developments: Track proposals from standards bodies (e.g., ISO/IEC, NIST) that address AI‑augmented vulnerability research and responsible disclosure.

Defensive AI agents: Monitor startups and research labs building AI systems that can not only discover but also automatically contain or neutralize high‑risk flaws before they are weaponized.

Ghiduri și chestionare conexe

Agenți AIEtica IAViitorul IATestați ceea ce știți — încercați un test AI gratuitCăutați un termen AI în glosarul nostruUrmați instrumentul de urmărire a reglementărilor AI
Ai găsit asta util?