For the first time, Google has revealed that it detected and prevented a zero-day exploit created with the assistance of artificial intelligence. The discovery was made by researchers at the Google Threat Intelligence Group (GTIG).
The exploit was being developed by prominent cybercrime threat actors and was intended for use in a mass exploitation event. If successful, the attack would have allowed the threat actors to bypass two-factor authentication on an unnamed open-source, web-based system administration tool.
Google’s researchers analyzed the Python script used in the exploit and found evidence suggesting AI involvement. Key indicators included a hallucinated CVSS score—a non-existent severity rating—and structured, textbook-style formatting consistent with large language model (LLM) training data.
The exploit targeted a yet-to-be-disclosed vulnerability in the system administration tool. While Google has not revealed the specific flaw, the company confirmed that it was actively exploited in the wild before being patched.
The incident underscores the growing sophistication of cyber threats enhanced by AI tools, which are increasingly being used to automate and refine attack strategies.