Google Thwarts First AI-Generated Zero-Day Exploit Targeting Web Admin Tools
Google’s Threat Intelligence Group identified and neutralized the first known zero-day exploit developed using artificial intelligence. Criminal hackers utilized large language models to discover a logic flaw in a popular open-source web administration tool, enabling two-factor authentication bypass. Although Google confirmed its own Gemini model was not used, the incident marks a significant escalation in cyber warfare, with state-sponsored actors from China and North Korea also leveraging AI for vulnerability research. The threat was patched before mass exploitation, highlighting the urgent need for advanced defensive strategies against AI-driven attacks.
Editorial summary awaiting refresh
Cross-source coverage
Wire timeline
Google Reports First AI-Generated Zero-Day Cyberattack
Google has identified the first known instance of cybercriminals utilizing artificial intelligence to create a zero-day vulnerability, marking a significant escalation in digital threats. According to a report by the Google Threat Intelligence Group, this undetectable exploit was developed with AI assistance, allowing attackers to bypass existing security measures before a fix was available. Google notified the affected unnamed company, which subsequently issued a patch to resolve the flaw. The findings indicate that advanced AI models are now being leveraged not just to discover vulnerabilities, but to actively construct them, increasing the speed and sophistication of attacks. While Google determined that Anthropic’s Claude Mythos model was likely not used for this specific exploit, it noted that state-linked groups, including Russia-associated hackers targeting Ukraine and North Korea’s APT45, are increasingly integrating AI into their cyber operations. John Hultquist, chief analyst at Google Threat Intelligence Group, warned that the race to weaponize AI for network infiltration has begun, suggesting many more AI-generated exploits may remain undiscovered. This development underscores the urgent need for enhanced cybersecurity defenses against AI-driven threats.
ProPakistaniGoogle Identifies First AI-Developed Zero-Day Exploit Bypassing Two-Factor Authentication
The Google Threat Intelligence Group (GTIG) has published a significant report detailing the emergence of artificial intelligence in sophisticated cybercrime operations. For the first time, researchers identified a zero-day exploit developed with the assistance of AI, specifically designed to bypass two-factor authentication (2FA) in a popular open-source web-based system administration tool. The malicious Python script exploited a logic flaw, demonstrating how large language models can analyze source code to identify unconsidered corner cases by contrasting developer intention with actual implementation. Beyond this specific incident, the report highlights a disturbing trend involving self-morphing malware capable of dynamically modifying its own source code and generating decoy scripts to evade detection. Additionally, attackers are utilizing Gemini-powered backdoors to enhance their intrusion capabilities. This development signals a new era in cybersecurity threats, where AI is not merely used for automation but for creative exploitation of complex enterprise logic. The findings underscore the evolving sophistication of black hat actors who leverage advanced contextual reasoning abilities of modern AI models to breach security systems that were previously considered robust against automated attacks.
Latest from Tom's HardwareGoogle Thwarts First Documented AI-Driven Zero-Day Attack
Google has successfully intercepted the first documented cyberattack in which hackers utilized artificial intelligence to discover and exploit previously unknown vulnerabilities, known as zero-day flaws. John Hultquist, chief analyst of Google's threat intelligence team, announced that a criminal group used a language model to identify a security flaw in a popular system administration tool, allowing them to bypass two-factor authentication. Google detected the intrusion and disrupted the operation before any harm occurred, notifying both the affected company and law enforcement. While no state sponsorship was confirmed, Google noted that groups linked to China and North Korea have explored similar techniques. This incident highlights growing industry concerns following Anthropic's recent announcement of its 'Mythos' AI model, which was restricted due to its potent hacking capabilities. Additionally, OpenAI has released a specialized cybersecurity version of ChatGPT for critical infrastructure managers. Hultquist warned that this case likely represents only a fraction of AI-assisted attacks, suggesting many more may remain undetected. The event marks a significant escalation in cybercrime tactics, demonstrating how advanced AI tools are being weaponized to automate vulnerability discovery and exploit security gaps faster than traditional defense mechanisms can respond.
Portada // elmundoGoogle Reports First AI-Assisted Zero-Day Attack Bypassing 2FA
Google’s Threat Intelligence Group has identified what it believes is the first instance of hackers using artificial intelligence to develop a zero-day exploit. The attack targeted a popular open-source, web-based system administration tool, allowing threat actors to bypass two-factor authentication (2FA) after obtaining valid user credentials. Google expressed high confidence that an AI model was leveraged to discover and weaponize the vulnerability, citing specific characteristics in the exploit script, such as hallucinations and formatting typical of AI training data. The vulnerability stemmed from a high-level semantic logic flaw rather than common implementation errors, suggesting the use of advanced large language models capable of identifying hardcoded trust assumptions. The report highlights an increasing trend of industrialized LLM abuse, where adversaries automate access to premium AI accounts to scale adversarial operations. While specific threat actors were not named, Google noted significant interest from China and North Korea in utilizing AI for vulnerability discovery. This development underscores the emerging risks within the AI software ecosystem, particularly as organizations integrate large language models into production environments, making integrated components like third-party data connectors primary targets for exploitation.
Cointelegraph.com NewsGoogle Thwarts First Confirmed Industrial-Scale AI-Powered Cyberattack
Google’s Threat Intelligence Group has confirmed the thwarting of the first known cyberattack utilizing artificial intelligence at an industrial scale. In this incident, a criminal hacking group employed an AI model to discover and exploit a zero-day vulnerability in a popular open-source web-based system administration tool. The exploit was designed to bypass two-factor authentication, potentially allowing attackers to compromise multiple organizations simultaneously. Google detected the threat before it could be deployed widely and alerted the software developer, enabling the release of a patch before any significant damage occurred. While Google did not disclose the specific hacking group, the targeted software, or the AI model used, it confirmed that its own Gemini model was not involved. The report highlights growing concerns about state-linked actors, particularly from China and North Korea, leveraging AI tools for vulnerability discovery. This event underscores the escalating risks in cybersecurity as AI capabilities advance, prompting the emergence of AI pentesting disciplines to counter adversarial inputs and protect critical infrastructure from increasingly sophisticated automated threats.
Digital TrendsGoogle Thwarts First AI-Powered Zero-Day Cyberattack
Google researchers have revealed that they successfully thwarted a sophisticated cyberattack utilizing artificial intelligence to discover and exploit a previously unknown zero-day vulnerability. This incident marks the first confirmed case of hackers using AI to identify software flaws unknown to developers. The attack targeted a popular open-source web-based system administration tool, aiming to bypass two-factor authentication if user credentials were known. Although the threat actors planned a mass exploitation event, Google's proactive counter-discovery prevented significant damage. The report highlights that the malware exhibited characteristics typical of Large Language Models, including excessive docstrings and hallucinated text. John Hultquist of the Google Threat Intelligence Group described this event as merely the tip of the iceberg, warning that AI-driven cybersecurity threats are likely to expand rapidly. This development intensifies concerns regarding AI safety, particularly following the recent release of Anthropic’s Claude Mythos model, which demonstrated capabilities to find zero-day vulnerabilities across major operating systems. The incident underscores the dual-use nature of advanced AI in both enhancing and compromising digital security infrastructure.
FuturismGoogle Detects Hackers Using AI to Discover Zero-Day Vulnerability for Mass Exploitation
Google has uncovered evidence that cybercriminals utilized an artificial intelligence program to identify a previously unknown zero-day vulnerability in a popular open-source web-based system administration tool. This marks the first instance where Google identified attackers leveraging AI to discover such flaws, which could have allowed hackers to bypass two-factor authentication and access victim accounts using only passwords. The attack code exhibited characteristics typical of large language models, including hallucinated CVSS scores and structured Pythonic formatting. Google's threat intelligence team proactively detected the threat and collaborated with the software vendor to patch the vulnerability before it could be exploited on a mass scale. Although Google’s own Gemini chatbot was not involved in the discovery, the company warns that this incident is likely just the tip of the iceberg. Analysts suggest that other AI-developed zero-day exploits probably exist and that state actors with significant resources are likely employing similar techniques. This development highlights an escalating arms race between AI-powered cyber defenses and increasingly sophisticated offensive capabilities used by criminal groups and nation-states.
PCMag.com - Technology Product Reviews, News, Prices & TipsGoogle Discovers First Zero-Day Exploit Developed Using AI
Google's Threat Intelligence Group (GTIG) has announced the first-ever discovery of a zero-day exploit believed to be developed using artificial intelligence. The group stated that its proactive security measures successfully intercepted a planned mass exploitation event, potentially preventing widespread damage. While Google confirmed that its own Gemini models were not utilized in the attack, it expressed high confidence that an AI model was instrumental in both identifying the vulnerability and weaponizing the exploit. The specific target remains unnamed, but the affected company was notified and has since patched the security issue. Although the threat actors were not explicitly identified, Google hinted at significant interest from groups associated with China and North Korea in leveraging AI for cyberattacks. John Hultquist, chief analyst at GTIG, described this incident as tangible evidence of a growing trend, calling it the tip of the iceberg for AI-driven cyber threats. This development underscores the dual nature of AI in cybersecurity, serving as both a tool for attackers and a critical component for defenders. Other tech firms, such as Anthropic with its Project Glasswing, are similarly employing AI to detect and mitigate high-severity vulnerabilities, highlighting an escalating arms race in digital security.
Engadget - Technology News & Expert ReviewsGoogle Thwarts First AI-Generated Zero-Day Exploit
The Google Threat Intelligence Group (GTIG) announced on May 11, 2026, that it identified and potentially prevented the first known zero-day exploit developed using artificial intelligence. According to GTIG's latest AI Threat Tracker, a criminal threat actor intended to use this exploit in a mass exploitation event targeting an open-source web-based system administration tool. The vulnerability allowed users to bypass two-factor authentication via a Python script. GTIG expressed high confidence that the attacker utilized an AI model to discover and weaponize the flaw, highlighting how advanced coding capabilities lower barriers for adversaries. Google collaborated with the affected vendor to responsibly disclose the issue and disrupt the threat. The report also detailed other emerging AI-driven threats, including autonomous malware operations, defense evasion techniques, and supply chain attacks targeting AI environments. This development underscores the dual-use nature of AI tools, which empower both defensive research and sophisticated cyberattacks. The International Monetary Fund recently emphasized that such AI-fueled cyber risks are now core financial stability issues, urging policymakers to treat cybersecurity with heightened priority amidst rapidly accelerating technological threats.
PYMNTS | | PYMNTS.comGoogle Reports Hackers Used AI to Exploit Zero-Day Vulnerability
Google cybersecurity researchers have uncovered a significant security incident where hackers utilized artificial intelligence to exploit a zero-day vulnerability. This discovery, reported by the Google Threat Intelligence Group (GTIG) on May 11, 2026, marks the first time the group has identified AI being used to weaponize such flaws. The attackers targeted a popular open-source web-based system administration tool, exploiting a weakness in a Python script to bypass two-factor authentication. While Google does not believe its own Gemini model or Anthropic’s Mythos model were specifically used, researchers express high confidence that an AI model aided in discovering and weaponizing the vulnerability. The report highlights how AI serves as both a sophisticated engine for adversary operations and a high-value target. It details how threat actors leverage AI for developing exploits, malware, autonomous command execution, and enhanced social engineering. This incident underscores the growing risk of AI-driven cybercrime, which has significantly lowered the cost of running convincing fraud campaigns and contributed to a rise in internet crime losses globally.
PYMNTS | | PYMNTS.comGoogle Reports First Use of AI to Create Zero-Day Security Flaw
Google has identified the first known instance of cybercriminals utilizing artificial intelligence to create a zero-day vulnerability, marking a significant shift in the cybersecurity landscape. According to a report by the Google Threat Intelligence Group, this development indicates that AI models are now being used not just to discover existing flaws, but to actively generate new, undetected exploits. While Google ruled out Anthropic's Claude Mythos model as the specific tool used, the report highlights broader trends, including Russia-linked groups employing AI to target Ukrainian networks and North Korean actor APT45 using AI to scale cyber operations. John Hultquist, chief analyst at Google, warned that the race to exploit AI for network vulnerabilities has already begun, suggesting that many more AI-generated zero-days likely exist unnoticed. The affected unnamed firm was notified and issued a patch before the report's public release. This event underscores how threat actors are leveraging AI to enhance the speed, scale, and sophistication of their attacks, posing new challenges for global digital security infrastructure.
SlashdotGoogle Thwarts First AI-Developed Zero-Day Exploit Targeting 2FA Systems
Google has successfully identified and neutralized a zero-day exploit that it claims was developed using artificial intelligence, marking a significant first in cybersecurity history. According to the Google Threat Intelligence Group (GTIG), prominent cybercrime actors intended to use this vulnerability for a mass exploitation event targeting an unnamed open-source web-based system administration tool. The attack aimed to bypass two-factor authentication by exploiting a semantic logic flaw where developers had hardcoded trust assumptions. Researchers detected AI involvement through specific indicators in the Python exploit code, such as a hallucinated CVSS score and structured formatting consistent with large language model training data. Although Google clarified that its own Gemini model was not used, the report highlights a growing trend of adversaries leveraging AI for persona-driven jailbreaking and refining exploit payloads. This incident underscores the escalating role of AI in both offensive cyber operations and defensive security measures, following recent concerns about AI-assisted vulnerability discovery in other platforms like Linux.
The VergeHackers Use AI to Create First Known Zero-Day 2FA Bypass for Mass Exploitation
Google has disclosed the identification of an unknown threat actor utilizing a zero-day exploit likely developed with artificial intelligence, marking the first known instance of AI being weaponized in the wild for vulnerability discovery and exploit generation. The Google Threat Intelligence Group (GTIG) reported that cybercriminals collaborated on a mass exploitation operation targeting a popular open-source web-based system administration tool. The exploit, implemented in a Python script, bypasses two-factor authentication (2FA) by leveraging a semantic logic flaw. GTIG assessed with high confidence that a large language model generated the code, citing characteristics such as educational docstrings and hallucinated CVSS scores. Although Google did not confirm the use of its Gemini AI, it highlighted similar abuses, including the PromptSpy Android malware which uses Gemini for autonomous operations and biometric data capture. Additionally, state-linked groups like UNC2814 and APT45 have attempted to misuse Gemini for espionage and repetitive prompting. Google worked with the affected vendor to patch the flaw and disabled assets related to the malicious activities, emphasizing the accelerating threat landscape where AI significantly reduces the effort required for attackers to identify and weaponize security vulnerabilities.
The Hacker NewsGoogle Researchers Foil AI-Generated Zero-Day Attack by Cybercrime Group
Security researchers at Google have reported that a cybercrime group utilized artificial intelligence to develop a hacking tool capable of exploiting a zero-day vulnerability in a widely used system administration software. This incident marks the first time Google’s Threat Intelligence Group has intercepted hackers using an AI-generated zero-day exploit in this manner. The AI model helped attackers identify a previously unknown flaw that could bypass multifactor authentication, potentially granting unauthorized access to organizational internal networks. Google maintained high confidence that AI was instrumental in discovering and weaponizing the exploit, though it declined to identify the specific cybercrime group, the affected software, or the large language model involved. However, the company confirmed that neither Anthropic’s Mythos nor its own Gemini model was used. Upon detection, Google alerted the software developer, who successfully patched the vulnerability before the hackers could deploy it against users. This event underscores the growing reality of AI-assisted cyber threats, prompting increased attention from government officials and technology leaders regarding the malicious potential of large language models.
Financial PostGoogle Warns of AI-Driven Cyberattacks After Disrupting Hacker Group
Google has issued a severe warning after successfully disrupting a criminal group's attempt to use artificial intelligence to exploit a zero-day vulnerability in an unnamed company's system. The attackers utilized a large language model to identify the security flaw, which allowed them to bypass two-factor authentication for a popular online system administration tool. John Hultquist, Google’s chief threat analyst, stated that this incident marks the arrival of the era of AI-driven exploitation, significantly accelerating the speed at which hackers can find and weaponize bugs. Although no damage occurred, the event highlights growing cybersecurity risks as AI capabilities advance, exemplified by recent models like Anthropic’s Mythos. The incident has intensified debates within the US government regarding AI regulation. The Trump administration, having repealed previous Biden-era guardrails, is now sending mixed signals on oversight, with some officials acknowledging the need for regulatory responses despite general opposition. Google noted that while no adversarial government was directly linked to this specific attack, state-sponsored groups from China and North Korea are exploring similar AI-enhanced techniques.
Fortune | FORTUNEGoogle Researchers Report First AI-Generated Zero-Day Attack Foiled
Google security researchers have reported with high confidence that a cybercrime group utilized artificial intelligence to discover and weaponize a zero-day exploit. This incident marks the first time Google’s Threat Intelligence Group has identified hackers using an AI-generated zero-day vulnerability in this manner. The attack targeted a widely used web-based system administration tool, aiming to bypass multifactor authentication to access internal organizational networks. Although Google declined to name the specific criminal group, the affected software, or the large language model employed, they confirmed the exploit was not created using Anthropic’s Mythos or Google’s Gemini models. The threat was neutralized after Google alerted the tool’s developer, who patched the flaw before it could be deployed against users. This development underscores growing concerns about the malicious use of AI in cybersecurity, following Anthropic’s decision to restrict its Mythos model due to national security risks. The White House has subsequently held emergency meetings with industry leaders to address these emerging threats, signaling that AI-driven cyberattacks are now a tangible reality for defenders.
The Straits Times World NewsGoogle Reports First Real-World Use of AI-Generated Zero-Day in Mass Hack Campaign
Google’s Threat Intelligence Group (GTIG) has identified the first known instance of cybercriminals using artificial intelligence to discover and weaponize a zero-day vulnerability for a planned mass-exploitation campaign. The targeted flaw was a two-factor authentication bypass in a popular open-source web administration platform, caused by hardcoded trust exceptions. Google intervened to patch the issue with the vendor before the attack could fully launch. The exploit code exhibited characteristics typical of Large Language Models, including educational docstrings and hallucinated CVSS scores, though Google confirmed its own Gemini model was not involved. GTIG warns that AI-assisted hacking has evolved beyond simple phishing, enabling attackers to identify high-level logic flaws rapidly. The report highlights that state-linked actors, including North Korea’s APT45 and Chinese operators, are also leveraging AI for vulnerability hunting and malware development. Google emphasizes that the AI vulnerability race is already underway, with criminals using these tools to enhance the speed, scale, and sophistication of attacks, marking a significant shift in the cybersecurity threat landscape.
www.theregister.com - ArticlesGoogle Reports First AI-Generated Zero-Day Exploit in Planned Mass Hack
Google’s Threat Intelligence Group (GTIG) has identified the first known real-world instance of cybercriminals using artificial intelligence to discover and weaponize a zero-day vulnerability. The flaw, a two-factor authentication bypass in a popular open-source web administration platform, was detected before a planned mass-exploitation campaign could fully launch. Google collaborated with the unnamed vendor to patch the issue, likely disrupting the operation. Analysis of the exploit code revealed characteristics typical of Large Language Models, including educational docstrings and hallucinated CVSS scores, indicating AI involvement in both identification and exploit creation. GTIG emphasizes that AI-powered hacking has evolved beyond simple phishing, now enabling attackers to find high-level logic errors efficiently. The report highlights that while this specific attempt was clumsy, state-backed groups from North Korea, China, and Russia are also leveraging AI for vulnerability hunting, malware generation, and influence operations. Google warns that the AI vulnerability race is already underway, urging organizations to recognize that threat actors are currently using these tools to enhance the speed, scale, and sophistication of their attacks, making AI-assisted exploitation a present danger rather than a future threat.
www.theregister.com - ArticlesZeroday: The Historic AI Attack That Wasn't
Google has announced a significant milestone in cybersecurity, claiming that cybercriminals utilized artificial intelligence to develop an attack exploiting a previously unknown zero-day vulnerability. According to a new report shared with DIE ZEIT, this incident marks the first known instance where AI was employed to identify and leverage such software errors before manufacturers could issue countermeasures. Zero-day vulnerabilities are critical security gaps that remain undisclosed to vendors, allowing hackers to exploit systems unchecked. However, Google clarified that their security teams successfully intercepted the attackers during the development phase, neutralizing the threat before it could be deployed. This announcement has reignited the ongoing debate regarding the impact of generative AI on cyber warfare. While some fear that AI tools will make attackers unstoppable by accelerating vulnerability discovery, others question whether this specific case represents a genuine paradigm shift or merely sophisticated marketing. The report underscores the dual-use nature of AI technology, highlighting both its potential to enhance offensive cyber capabilities and the necessity for advanced defensive measures. As AI integration deepens across industries, the cybersecurity landscape faces evolving challenges in predicting and mitigating AI-assisted threats.
DIE ZEIT | Nachrichten, News, Hintergründe und DebattenGoogle Reports First Use of AI to Create Zero-Day Security Flaw
Google has reported the first confirmed instance of hackers using artificial intelligence to create a zero-day security vulnerability, marking a significant escalation in the cybersecurity landscape. The Google Threat Intelligence Group stated that this development indicates the race to utilize AI for discovering and exploiting network vulnerabilities has already begun. While Anthropic’s Claude Mythos model was identified as a powerful tool for finding vulnerabilities, Google concluded it was likely not used to create this specific exploit. The report highlights growing concerns among US policymakers, including the Trump administration, regarding the regulation of advanced AI models like OpenAI’s GPT-5.5-Cyber. John Hultquist, chief analyst at Google, warned that threat actors are leveraging AI to increase the speed, scale, and sophistication of cyberattacks. This incident follows recent observations of AI-enhanced attacks by state-linked groups from China, Russia, and North Korea. In response to the heightened risk, tech companies are implementing staged releases of advanced models to maintain a temporary defensive advantage for security researchers and government agencies, though experts warn this window may only last months.
Politics, Policy, Political News Top Stories