Google has confirmed the first known zero-day exploit developed using artificial intelligence. The company published its AI Threat Tracker report on May 11, 2026. The report details how a cybercrime group used an AI model to write a Python exploit script. This marks a significant shift in the landscape of digital security threats.
Analysts say AI vulnerability race is already underway
The AI-generated exploit targeted a popular open-source web administration tool. It successfully bypassed two-factor authentication by exploiting a semantic logic error. Traditional security scanners missed this vulnerability because it relied on a hardcoded trust assumption. Google worked with the affected vendor to patch the flaw before the planned mass exploitation campaign could proceed.
Analysts note that the AI vulnerability race is already underway. GTIG chief analyst John Hultquist stated that for every zero-day traced back to AI, many more likely exist. The Register observed that this appears to be the clumsy early phase of AI weaponization. The report also highlights broader AI weaponization by threat groups including APT45, UNC2814, and TeamPCP.
The exact identity of the AI model used by the attackers remains unclear. Google confirmed that neither its own Gemini models nor Anthropic's Mythos were involved. The exploit script showed signs of being AI-generated, including educational docstrings and hallucinated CVSS scores. Google's Threat Intelligence Group disrupted the attack, but the broader implications of AI-driven exploits continue to evolve.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.