ThinkPatternGet the app
Story
TECHNOLOGY · MAY 11, 2026

Google Disrupts First AI-Developed Zero-Day Exploit Campaign

Google Threat Intelligence Group blocked a mass cyberattack involving the first known zero-day exploit developed using artificial intelligence to bypass two-factor authentication.

The Google Threat Intelligence Group (GTIG) disrupted a criminal group's attempt to launch a mass exploitation campaign using the first known zero-day exploit developed with artificial intelligence. The AI-generated Python script targeted a semantic logic flaw in a popular open-source web-based administration tool, which would have allowed attackers to bypass two-factor authentication. Researchers identified the AI's involvement through hallmark signs such as educational annotations, textbook-style formatting, and a hallucinated CVSS severity score.

GTIG worked with the affected vendor to patch the vulnerability before the attack could be executed. While Google ruled out its own Gemini model as the source of the exploit, the company's AI Threat Tracker report warns that threat actors are now operationalizing AI to accelerate vulnerability research and malware development. This includes the PROMPTSPY Android backdoor, which uses AI for autonomous device control and biometric data theft.

The report highlights significant activity from state-sponsored actors. North Korea's APT45 used AI to recursively analyze security blind spots and validate exploits at scale, while China-linked groups, including UNC2814, attempted to jailbreak Gemini to probe router firmware. Additionally, Russia-linked groups utilized AI-generated decoy code to evade detection in networks within Ukraine. To maintain access to premium models, attackers are using shadow API services and proxy relays to bypass safety guardrails.


Reported across 176 outlets
Actors
Government of ChinaFederal Government of RussiaJohn Hultquist

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play