Google Reports Hackers Used AI to Build Zero-Day Attack
Google's Threat Intelligence Group reported on May 12, 2026 that hackers used an AI large language model to create the first observed zero-day exploit targeting a system administration tool to bypass multifactor authentication. Google has high confidence AI was used but declined to name the threat actor or LLM involved, ruling out Anthropic's Mythos—which Anthropic withheld in April 2026 citing national security risk—and Google's Gemini. The vulnerability was patched before deployment.
AI-generated zero-day exploit
▪Google researchers do not believe the exploit was created using Anthropic PBC's Mythos or Google's own model Gemini.
▪Google has high confidence that AI was used to help discover and weaponize the exploit.
▪Security researchers at Alphabet Inc.'s Google believe a cybercrime group used artificial intelligence to create a hacking tool that can bypass defenses in a widely-used tool to administer computer systems.
▪Google's Threat Intelligence Group caught a hacker using an AI-generated zero-day exploit for the first time.
Multifactor authentication bypass vulnerability
▪The hacking group used an AI model to find a previously unknown flaw in a system administration tool that could be used to bypass multifactor authentication.
▪The vulnerability could be used to gain access to the internal networks of organizations using the affected software.
Google threat intelligence discovery
▪Google's Threat Intelligence Group published a report on the AI-generated zero-day exploit on May 12, 2026.
▪Google declined to name the cybercrime group involved in the attempted attack.
▪Google declined to name the impacted software in the attempted attack.
▪Google declined to name the large language model that was used in the attempted attack.
Developer notification before deployment
▪Google alerted the tool's developer about the vulnerability, who fixed the issue before hackers could deploy it against users.
▪The scheme was foiled when Google alerted the tool developer.
National security implications
▪The White House has moved to address potential malicious use of large language models following Anthropic's April 2026 announcement.
▪Government officials have held emergency meetings with technology and industry leaders following Anthropic's April 2026 announcement about Mythos.
▪Anthropic said in April 2026 it would not widely release its new model Mythos because the way it used AI to identify and exploit software flaws posed a national security risk.
Story comments
Loading comments…