Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Google spotted an AI-developed zero-day before attackers could use it  – CyberScoop
AttackFeed by Joe Wagner | Google spotted an AI-developed zero-day before attackers could use it  - CyberScoop

Google spotted an AI-developed zero-day before attackers could use it  – CyberScoop

Posted on May 11, 2026 By Matt Kapko No Comments on Google spotted an AI-developed zero-day before attackers could use it  – CyberScoop
Attack Feeds

Google researchers found a zero-day exploit developed by artificial intelligence and alerted the susceptible vendor to the imminent threat before a well-known cybercrime group initiated a mass-exploitation campaign, the company said in a report released Monday.

The averted disaster probably isn’t the first time attackers used AI to build a zero-day, but it is the first time Google Threat Intelligence Group found compelling evidence that this long-predicted and worrying escalation in vulnerability-exploit development is underway.

“We finally uncovered some evidence this is happening,” John Hultquist, chief analyst at GTIG, told CyberScoop. “This is probably the tip of the iceberg and it’s certainly not going to be the last.”

Google declined to identify the specific vulnerability, which has been patched, or name the “popular open-source, web-based administration tool” it affected. It did, however, note that the defect impacted a Python script that allows attackers to bypass two-factor authentication for the service.

Researchers also withheld details about how they discovered the zero-day exploit or the cybercrime group that was preparing to use it for a large-scale attack spree.

The threat group has a “strong record of high-profile incidents and mass exploitation,” Hultquist said, suggesting the attackers are prominent and well-known among cybersecurity practitioners. 

GTIG is fairly confident the threat group was using AI in a meaningful way throughout the entire process, but it has yet to determine if the technology also discovered the vulnerability it ultimately developed into an exploit.

Whichever AI model the attackers used — Google is confident it wasn’t Gemini or Anthropic’s Mythos — left artifacts throughout the exploit code that are inconsistent with human developers. This evidence, which included documentation strings in Python, highly annotated code and a hallucinated but non-existent CVSS score, tipped Google off to the fact AI was heavily involved, Hultquist said. 

GTIG has been warning about and expecting AI-developed exploits to hit systems in the wild, especially after its Big Sleep AI agent found a zero-day vulnerability in late 2024.

“I think the watershed moment was two years ago when we proved this was possible,” Hultquist said, adding that there are probably several other AI developed zero-days in play now. 

Yet, to him, the discovery of a zero-day exploit developed by AI is less concerning than what this single instance forebodes even further.

“The game’s already begun and we expect the capability trajectory is pretty sharp,” Hultquist said. “We do expect that this will be a much bigger problem, that there will be more devastating zero-day attacks done over this, especially as capabilities grow.”

The post Google spotted an AI-developed zero-day before attackers could use it appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Hackers Exploit Vercel GenAI to Mass-Produce Convincing Phishing Sites  – Hackread – Cybersecurity News, Data Breaches, AI and More
Next Post: Lyrie.ai Joins First Batch of Anthropic’s Cyber Verification Program  – Hackread – Cybersecurity News, Data Breaches, AI and More ❯

You may also like

AttackFeed by Joe Wagner | Browser Extensions Are the New AI Consumption Channel That No One Is Talking About  - The Hacker News
Attack Feeds
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About  – The Hacker News
April 10, 2026
AttackFeed by Joe Wagner | Apple discloses first actively exploited zero-day of 2026  - CyberScoop
Attack Feeds
Apple discloses first actively exploited zero-day of 2026  – CyberScoop
February 12, 2026
AttackFeed by Joe Wagner | Product Walkthrough: How Mesh CSMA Reveals and Breaks Attack Paths to Crown Jewels  - The Hacker News
Attack Feeds
Product Walkthrough: How Mesh CSMA Reveals and Breaks Attack Paths to Crown Jewels  – The Hacker News
March 18, 2026
AttackFeed by Joe Wagner | Where Multi-Factor Authentication Stops and Credential Abuse Starts  - The Hacker News
Attack Feeds
Where Multi-Factor Authentication Stops and Credential Abuse Starts  – The Hacker News
March 5, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.