Google released a report on May 11 detailing the industrialization of artificial intelligence in cyberattacks. The Google Threat Intelligence Group (GTIG) documented how threat actors are leveraging AI to discover vulnerabilities and develop exploits. The report highlights a shift toward automated and sophisticated digital threats.
Attackers from China and North Korea use AI models to audit firmware and find weaknesses
Attackers from China and North Korea are using AI models like Gemini to audit firmware for TP-Link devices. These actors also analyzed the Odette file transfer protocol to find weaknesses. An AI-developed Python script successfully exploited a zero-day vulnerability in an open-source system management tool. This exploit allowed attackers to bypass two-factor authentication.
Threat actors use AI for code obfuscation, automating malware behavior, and impersonating journalists. Attacks are increasingly targeting AI development environments. Malware disguised as OpenClaw skill packages and supply chain attacks on GitHub Actions by TeamPCP demonstrate this trend. Google is deploying defensive AI tools such as Big Sleep for vulnerability discovery and CodeMender for automatic code repair.
The report frames the current cybersecurity landscape as one where AI abuse has become industrialized. The intersection of AI technology and cybersecurity threats defines the new attack surface. Software vulnerabilities and development environment attacks remain central to these operations. The findings suggest that defensive measures must also evolve to counter automated threats.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.