Safety

Google says it identified and stopped a zero-day crafted with AI

Google's Threat Intelligence Group reported that it detected and neutralized a zero-day vulnerability created with the assistance of artificial intelligence.

Google's Threat Intelligence Group (GTIG) reports that its security researchers detected and neutralized a zero-day vulnerability that appears to have been developed with the assistance of artificial intelligence. The Verge published the account of the incident.

According to GTIG, the attackers planned to exploit the vulnerability to bypass two-factor authentication on an unnamed service, enabling what the team described as potential "mass attack operations."

Investigators found references in Python scripts intended for the attack that suggest the use of AI in creating the exploit. Google says this is the first instance it has identified where AI was involved in preparing a zero-day attack.

The researchers also stressed that, based on their analysis, the attackers likely did not use Google's Gemini model to build the exploit. The specific attack was prevented, but GTIG warned that threat actors are increasingly turning to AI to find and weaponize security flaws.

This incident highlights new defensive challenges as attackers leverage automation and machine-learning tools: AI can speed up vulnerability discovery and scale offensive tooling, which requires defenders to update detection and mitigation tactics accordingly.

Key points to watch

  • GTIG found that the attack aimed to bypass two-factor authentication on an unnamed service.
  • Python scripts linked to the attack contained indicators of AI use, though Gemini was likely not involved according to Google.
  • The attack was stopped, but organizations should harden defenses because AI can accelerate the discovery and exploitation of vulnerabilities.

Google and other security teams are now paying closer attention to signs that automated tools and models may have been used in constructing attacks, and are adapting their defenses to the growing role of AI in cybercrime.