35 Sources
[1]
Google stopped a zero-day hack that it says was developed with AI
For the first time, Google says it has spotted and stopped a zero-day exploit developed with AI. According to a report from Google Threat Intelligence Group (GTIG), "prominent cyber crime threat actors" were planning to use the vulnerability for a "mass exploitation event" that would have allowed
[2]
Google finds first AI-developed zero-day that bypasses 2FA -- self-morphing malware and Gemini-powered backdoors signal a new era of cybercrime
The Google Threat Intelligence Group (GTIG) has just published a report on the hacktivities of blackhats everywhere, and the painted picture is quite sobering. Not only are attackers predictably using clankers to automate their efforts, but they're also putting them to rather creative use in almost
[3]
Google Spots Hackers Using AI To Find Zero-Day Flaw For Mass Explotation
When he's not battling bugs and robots in Helldivers 2, Michael is reporting on AI, satellites, cybersecurity, PCs, and tech policy. In an unsettling sign of what's to come, Google has uncovered evidence that hackers used an AI program to find a previously unknown software vulnerability that could
[4]
Google says criminals used AI-built zero-day in planned mass hack spree
GTIG says AI-powered hacking has moved well beyond phishing emails and chatbot tricks Google says crooks already have AI cooking up zero-days, and claims one nearly escaped into the wild before the company stopped it. In a report shared with The Register ahead of publication on Monday, Google's
[5]
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerability discovery and
[6]
Google: Hackers used AI to develop zero-day exploit for web admin tool
Researchers at Google Threat Intelligence Group (GTIG) say that a zero-day exploit targeting a popular open-source web administration tool was likely generated using AI. The exploit could be leveraged to bypass the two-factor authentication (2FA) protection in a popular open-source, web-based
[7]
Google disrupts hackers using AI to exploit an unknown weakness in a company's digital defense
Google said Monday that it had disrupted a criminal group's attempt to use artificial intelligence to exploit another company's previously unknown digital vulnerability, adding to heightened worries across government and private industry about AI's risks for cybersecurity. Google shared limited
[8]
Google says it likely thwarted effort by hacker group to use AI for 'mass exploitation event'
Google's Threat Intelligence Group said in a report on Monday that it thwarted an effort by hackers to use artificial intelligence models to "plan a mass vulnerability exploitation operation." The group, known by the acronym GTIG, said it has "high confidence" that it recorded hackers using an AI
[9]
Google announces its first-ever discovery of a zero-day exploit made with AI - Engadget
We can now add cybercrimes to the list of growing concerns associated with artificial intelligence. Google's Threat Intelligence Group (GTIG) said it discovered, for the first time ever, a threat actor using a zero-day exploit that it believes was developed by AI." Zero-day vulnerabilities are
[10]
Google identifies first AI-developed zero-day exploit and thwarts planned mass exploitation event
Google has identified the first zero-day exploit it believes was developed with artificial intelligence. The criminal threat actor that built it planned to use it in a mass exploitation event. Google's Threat Intelligence Group discovered the vulnerability before it was deployed, worked with the
[11]
Google just blocked a zero-day exploit made with AI
The report also highlights growing interest from state-linked hacking groups connected to China and North Korea in using AI for exploit research and vulnerability discovery. This means governments and organized cyber groups are increasingly exploring how AI can help them break into systems faster
[12]
Google Says It Found Evidence of Hackers Using AI to Discover a Zero-Day Vulnerability
The tech giant says this is the first time it has identified such a case. As AI models continue to get more powerful, it’s not too surprising that some people are trying to use them for crime. The Google Threat Intelligence Group said on Monday that it has identified, for the first time, a
[13]
Google warns hackers now using AI to create new software exploits
In what could be the first confirmed case of hackers using AI to develop a zero-day exploit, Google says threat actors attempted to weaponize a previously unknown vulnerability capable of bypassing two-factor authentication on a popular web-based administration tool. The company said it detected
[14]
AI-assisted hacking is already here, Google warns
Why it matters: Security researchers have long warned AI could one day accelerate cyberattacks. That day appears to be here. Driving the news: Google's threat intelligence group said in a report Monday that it found evidence of several "prominent cyber crime threat actors" partnering to identify a
[15]
'This is the tip of the iceberg': Google experts say they have seen hackers using AI to discover and weaponize a zero-day for the first time
* GTIG spotted threat actors using AI to identify and exploit a zero-day * The vulnerability allowed for two-factor authentication bypass * AI is capable of 'reading' developer intent, and can 'see' how hardcoded exceptions relate to security enforcement Threat actors are leveraging AI at a new
[16]
AI-powered hacking has exploded into industrial-scale threat, Google says
Criminal groups and state-linked actors appear to be using commercial models to refine and scale up attacks In just three months, AI-powered hacking has gone from a nascent problem to an industrial-scale threat, according to a report from Google. The findings from Google's threat intelligence
[17]
'It's here': Google issues dire warning after catching hackers using AI to break into computers | Fortune
Google shared limited information about the attackers and the target, but John Hultquist, chief analyst at the tech giant's threat intelligence arm, said it represents a moment cybersecurity experts have warned about for years: malicious hackers arming themselves with AI to supercharge their
[18]
Google Alarmed by Formidable AI-Powered Zero-Day Cyberattack
Can't-miss innovations from the bleeding edge of science and tech Google was rattled by a cyberattack that used AI to unearth a major flaw in its software that its own developers had no idea about. The attack, which the New York Times reports was ultimately thwarted, was revealed by researchers
[19]
Google says AI is being abused at industrial scale for cyberattacks, and it just thwarted one
Hackers used AI to find a hidden software flaw and nearly launched a mass cyberattack before Google stepped in. For years, security experts warned that AI would eventually give hackers a dangerous new edge. That moment has arrived. Google's Threat Intelligence Group has published a report
[20]
Hackers Used AI to Build a Zero-Day Exploit That Bypasses Two-Factor Authentication: Google - Decrypt
Google worked with the affected vendor to patch the vulnerability before the campaign scaled, but said threat actors linked to China and North Korea are also actively using AI for vulnerability research and exploit development. Cybercriminals used an AI model to discover and weaponize a zero-day
[21]
Read our new report on AI-powered threats and our latest defenses.
Today we're releasing a report that details the latest observations from Google Threat Intelligence Group (GTIG). The findings include the first time we've identified an attacker, or threat actor, using a zero-day exploit that we believe was developed with AI. The threat actor planned to use the
[22]
Google disrupts hackers using AI to exploit an unknown weakness in a company's digital defense
Google said Monday that it had disrupted a criminal group's attempt to use artificial intelligence to exploit another company's previously unknown digital vulnerability, adding to heightened worries across government and private industry about AI's risks for cybersecurity. Google shared limited
[23]
Google says criminals used AI to build a working zero-day exploit for the first time - SiliconANGLE
Google says criminals used AI to build a working zero-day exploit for the first time Criminal hackers have used artificial intelligence to develop a working zero-day exploit, the first confirmed case of its kind, according to a report released today by Google LLC's Google Threat Intelligence
[24]
Google detects AI-assisted cyber exploit before mass attack
Google's Threat Intelligence Group (GTIG) announced the discovery of a zero-day exploit believed to be developed by artificial intelligence, marking a significant first in cybersecurity. The exploit was reportedly designed for a "mass exploitation event," and Google stated that its proactive
[25]
Google finds hackers using AI to discover and develop a zero-day exploit for the first time for mass attacks
With AI models achieving new milestones, it was inevitable that security experts' fears would come true. Google's Threat Intelligence Group has, for the first time, discovered a threat actor using a zero-day exploit likely developed with AI. A zero-day vulnerability is a software or hardware flaw
[26]
Google Finds First AI-Developed Zero-Day Exploit
Google's Threat Intelligence Group says it has "high confidence" a threat actor used an AI model to help discover and weaponize a vulnerability in a popular system admin tool. Google's Threat Intelligence Group says it identified what it believes is the first-ever case of hackers using artificial
[27]
Hackers used AI to build a working cyberattack for the first time - Phandroid
Security researchers have been warning for years that AI would eventually make its way into the hands of hackers looking to build more sophisticated attacks. Google's Threat Intelligence Group (GTIG) just confirmed it's no longer a warning. The group says it has discovered the first known
[28]
Google Detects the First Instance of a Hacker Using AI-Developed Exploit
Researchers believe AI-enabled malware can accelerate autonomous attacks Google Threat Intelligence Group (GTIG) shared a series of developments in the cybercrime space on Tuesday. The group highlighted that, currently, artificial intelligence (AI) is being used both as an engine for adversary
[29]
Google Thwarts First AI-Generated Zero-Day Exploit | PYMNTS.com
By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions. Writing in the latest GTIG AI Threat Tracker, which was released Monday (May
[30]
Google Research Highlights AI-Created Hack That Found and Almost Used Unknown Vulnerabilities
Coming at a time when Anthropic and OpenAI are seeking to build-up their AI models as cybersecurity solutions, Google's warning need to be taken seriously while building guardrails to AI solutions Google's Threat Intelligence Group (GTIG) might have just set the cat amongst the pigeons. While
[31]
Google Uncovers Hackers Using AI for Zero-Day Attack | PYMNTS.com
By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions. The discovery is a first for the Google Threat Intelligence Group (GTIG), which
[32]
Google disrupts hackers using AI to exploit an unknown weakness in a company's digital defence
Google said Monday that it had disrupted a criminal group's attempt to use artificial intelligence to exploit another company's previously unknown digital vulnerability, adding to heightened worries across U.S. government and private industry about AI's risks for cybersecurity. Google shared
[33]
Google disrupts AI hackers to exploit unknown weakness in firm's digital defence | BreakingNews
Google said it had disrupted a criminal group's attempt to use artificial intelligence to exploit another company's previously unknown digital vulnerability, adding to heightened worries across government and private industry about AI's risks for cybersecurity. Google shared limited information
[34]
Google Threat Report Warns AI-Driven Cyber Operations Are Scaling Across Global ...
Cyber threat actors are increasingly integrating artificial intelligence into real-world cyber operations, according to a new report from Google Threat Intelligence Group (GTIG), which warns the technology is now being used to accelerate everything from vulnerability research to phishing, malware
[35]
Google stops advanced AI attack designed to bypass two-factor authentication, here is how
Hackers are also using techniques like 'persona-driven jailbreaking.' Google has revealed that it detected and stopped a cyberattack that appears to have been developed with the help of AI. According to a report by Google Threat Intelligence Group (GTIG), cybercriminals were preparing to use a
Share
Copy Link
Google Threat Intelligence Group identified and stopped the first AI-developed zero-day exploit targeting two-factor authentication systems. Cybercrime groups had planned a mass exploitation event using the vulnerability before Google's intervention disrupted the operation. The discovery signals a new phase in the AI vulnerability race.
Google has identified and stopped what it says is the first AI-developed zero-day exploit discovered in the wild, marking a significant escalation in how cybercrime groups are leveraging artificial intelligence
1
. The Google Threat Intelligence Group uncovered prominent cyber crime threat actors planning to use the vulnerability for a mass exploitation event targeting an open-source web administration tool2
. The AI-generated zero-day exploit was designed to bypass two-factor authentication, allowing attackers to access victim accounts using only password credentials3
.
Source: Digit
Google's investigators identified several telltale signs that large language models assisted in exploit development. The Python script contained educational docstrings, a hallucinated CVSS score, and structured, textbook Pythonic formatting highly characteristic of LLM training data
5
. The 2FA bypass exploited a high-level semantic logic flaw where developers hardcoded a trust assumption in the platform's authentication system1
. According to the Google Threat Intelligence Group, while frontier LLMs struggle with complex enterprise logic flows, they excel at contextual reasoning—reading source code to validate developer intention versus actual implementation and quickly identifying unconsidered corner cases2
.
Source: Android Authority
John Hultquist, chief analyst at Google Threat Intelligence Group, emphasized that the AI vulnerability race is not imminent—it has already started. "For every zero-day we can trace back to AI, there are probably many more out there," Hultquist stated
4
. He challenged observers to focus on the bigger picture: if criminals are using AI in cybercrime, state-sponsored hackers with significant resources probably are too3
. Google worked with the impacted vendor to responsibly disclose the vulnerability and disrupt the threat activity before the mass exploitation campaign could launch5
.Related Stories
Beyond exploit generation, AI in cybercrime has expanded to self-morphing malware capable of modifying its own source code in real-time to evade detection
2
. The PROMPTSPY Android backdoor leverages Google Gemini to autonomously navigate infected devices, taking screenshots and interpreting UI elements to simulate user interactions, including capturing PIN authentication and intercepting uninstall button clicks2
. This malware demonstrates high operational resilience, allowing attackers to rotate critical components like command-and-control infrastructure and Gemini API keys at runtime without redeploying the payload5
.
Source: Phandroid
Google's report reveals pervasive AI usage across multiple cybersecurity operation types. North Korean group APT45 has been using AI to process thousands of exploit checks and expand its toolkit, while Chinese state-linked operators experiment with AI systems for vulnerability hunting and automated target probing
4
. Phishing campaigns now leverage bots to generate organizational charts and craft custom emails using real information from LinkedIn pages and press releases, with financial, internal security, and human resources departments serving as prime targets2
. Russian influence operations have been detected using AI to generate believable voiceovers and subtly alter facial expressions in real video footage, interspersing fabricated content with legitimate news for disinformation campaigns2
. Ryan Dewhurst, watchTowr's Head of Threat Intelligence, noted that AI is already accelerating vulnerability discovery, reducing the effort needed to identify, validate, and weaponize flaws—compressed timelines are today's reality, not a future concern5
.Summarized by
Navi
[2]
12 Feb 2026•Technology

05 Nov 2025•Technology

02 Sept 2026•Technology

1
Science and Research

2
Policy and Regulation

3
Technology