Google's Threat Intelligence Group detected the first zero-day exploit built with AI assistance on May 11, 2026. A criminal hacking group wrote the exploit as a Python script to bypass two-factor authentication in an open-source web admin tool. Google worked with the vendor to prevent mass exploitation. China and North Korea linked hackers have shown strong interest in using AI to find software flaws, with groups employing techniques like persona-driven jailbreaking.
First AI-generated zero-day exploit
- ▪The Python script had unusually detailed educational docstrings, a hallucinated CVSS severity score, and formatting typical of large language model output
- ▪Google worked with the vendor to stop mass exploitation of the AI-generated zero-day exploit before mass exploitation started
- ▪Google's Threat Intelligence Group detected what Google believes is the first zero-day exploit built with help from an AI model on May 11, 2026
- ▪A criminal hacking group wrote the AI-assisted zero-day exploit as a Python script to bypass two-factor authentication in an open-source web admin tool
State-backed AI vulnerability research
- ▪Chinese threat group UNC2814 directed an AI model to search TP-Link embedded device firmware and Odette File Transfer Protocol implementations for remote code execution vulnerabilities
- ▪Chinese threat group UNC2814 attacks telecom and government targets
- ▪North Korean group APT45 sent thousands of repetitive prompts to recursively analyze known CVE entries and validate proof-of-concept exploits
- ▪China and North Korea linked hackers have shown a strong interest in using AI to find and take advantage of software flaws, according to Google's Threat Intelligence Group
- ▪Chinese threat group UNC2814 used a technique Google calls persona-driven jailbreaking to instruct an AI model to behave as a senior security auditor
AI-enabled malware development
- ▪PROMPTSPY enables attackers to hand off operational decisions to the AI model itself
- ▪Suspected Russian hackers have used AI to code and build polymorphic malware and obfuscation networks
- ▪Google described PROMPTSPY as malware that uses AI models to interpret system states and dynamically generate commands to manipulate victim environments
- ▪TeamPCP, also known as UNC6780, has begun targeting AI software dependencies as an entry point into broader networks for ransomware deployment and extortion
Threat actor AI access methods
- ▪Threat actors procure anonymized premium-tier access to language models via specialized middleware and automated account registration systems
- ▪Specialized middleware and automated account registration systems enable hackers to circumvent usage restrictions en masse by utilizing trial accounts to finance their activities
Google defensive AI tools
- ▪Google disables accounts caught misusing Gemini for malicious purposes
- ▪Google uses Big Sleep, an AI agent that identifies software vulnerabilities, as a defensive AI tool
- ▪Google uses CodeMender, which uses Gemini's reasoning to automatically patch flaws, as a defensive AI tool
Perspective of Criminal and state-backed hacking groups
- ▪North Korean group APT45 sent thousands of repetitive prompts to recursively analyze known CVE entries and validate proof-of-concept exploits
Story comments
Loading comments…