Google Threat Intelligence Group Detects First Known Instance of AI-Developed Zero-Day Exploit in Action

Google says the AI-developed zero-day exploit was planned to be used in a mass exploitation event.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 13 May 2026 12:15 IST
Highlights
  • GTIG was able to stop it using proactive counter discovery
  • Google says threat actors have shown a high interest in AI
  • Researchers believe AI-enabled malware can accelerate autonomous attacks

Google says threat actors are increasingly using AI for vulnerability discovery and cyberattacks

Photo Credit: Reuters

Google Threat Intelligence Group (GTIG) shared a series of developments in the cybercrime space on Tuesday. The group highlighted that, currently, artificial intelligence (AI) is being used both as an engine for adversary operations and as a high-value target for attacks. The most concerning development is the first known instance where a threat actor used an AI-developed zero-day exploit. While the attack was foiled by the tech giant, this raises fresh concerns over AI bolstering hackers and threat actors.

Google Says AI Is Becoming Part of Real-World Cyberattacks

In a blog post, Google's cybersecurity research arm revealed several developments in which AI is being used to carry out cyberattacks. GTIG says threat actors are no longer using AI only for simple phishing emails or text generation. Instead, attackers are now applying generative AI models to more advanced parts of cyber operations, including vulnerability research, exploit development, malware creation, and defence evasion.

Advertisement

One of the key findings in the report is a planned mass exploitation campaign involving a zero-day vulnerability. A zero-day is a software flaw unknown to the vendor at the time attackers begin exploiting it. GTIG said it identified a threat actor using a zero-day exploit that it believes was developed with assistance from AI tools. Google said it discovered the vulnerability before the attackers could use it at scale and worked with the affected vendor to patch the issue.

The exploit reportedly targeted a popular open-source web administration tool and allowed attackers to bypass two-factor authentication (2FA), a security system that normally requires a second verification step in addition to a password.

Google said signs within the exploit code suggested AI involvement. These included AI-style coding patterns, explanatory comments, and even a fabricated vulnerability severity score generated in a format commonly associated with large language models.

Beyond vulnerability discovery, GTIG said attackers are also using AI to accelerate malware development and improve operational efficiency. According to the report, AI-assisted coding is helping threat actors create more adaptable malware and obfuscation systems designed to evade security software.

Advertisement

Google specifically pointed to malware families such as PROMPTSPY, which the company described as an example of AI-enabled malware capable of interpreting system states and dynamically generating commands. In simpler terms, the malware can adapt its behaviour depending on the environment it encounters on an infected machine.

The report also said attackers linked to China, North Korea, and Russia have shown increasing interest in using AI models for vulnerability research and attack workflows. In some cases, threat actors reportedly used AI systems to analyse known vulnerabilities, validate proof-of-concept exploits, and improve malicious infrastructure.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Samsung Galaxy S26 FE Specifications Leaked Ahead of Likely September Launch
  2. iQOO Neo 11 Ultra Full Specifications List Revealed via China Telecom Site
  3. Panasonic Lumix L10 Fixed Lens Camera Debuts in India at This Price
  4. Spider-Man: Brand New Day Has Lifted Sales of Spider-Man 2 on PS5 and PC
  5. Asus Targets No. 1 Position in India This Year: VP Arnold Su on Tablets, Pricing, and More
  6. Asus and Lenovo's Googlebook Laptops Leak Ahead of Launch
  7. Dyson Airwrap i.d. Hair Styler Launched in New Colour Option in India
  8. Vivo X500 Series Design, Display and Camera Details Leak Ahead of Launch
  9. Here's How Much the Vivo X300 FE Costs in India After Price Hike
  10. Redmi Note 17 Review
  1. Amazon Great Freedom Sale 2026: Top Smartphone Deals From Leading Brands
  2. Amazon Great Freedom Sale 2026: Best Deals on Smartphones Under Rs 1 Lakh
  3. Bitcoin Miner Riot Platforms Enters $9 Billion AI Infrastructure Deal With Anthropic: Report
  4. Alan Wake 2 Has Crossed 3 Million Copies Sold Nearly 3 Years After Launch, Remedy Confirms
  5. Amazon Great Freedom Sale 2026: Best Deals on Smart Water Purifiers
  6. Redmi K100 Pro Max and Redmi K100 Pro Launched With 185Hz AMOLED Display, 200-Megapixel Camera: Price, Features
  7. Amazon Great Freedom Sale 2026: Best Deals on TWS Under Rs. 3,000
  8. Noise Clutch HP-P01 Gaming Headphone Launched in India With 50mm Driver, Up to 40 Hours Battery Life: Price, Features
  9. OpenAI Launches GPT-5.6-Cyber Model Through Daybreak to Strengthen Cyber Defence
  10. Marvel's Spider-Man 2 Has Reportedly Sold Over 300,000 Copies Since Spider-Man: Brand New Day Released
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.