Google has publicly acknowledged for the first time that hackers used artificial intelligence to discover and mass-exploit a previously unknown zero-day vulnerability. According to the company, attackers leveraged a flaw in a widely used piece of software; Google did not identify the affected system but said the bug has been patched. The intrusion was stopped by the Google Threat Intelligence Group before it could cause global damage.
The case is particularly serious because the attackers found a method that could bypass two-factor authentication — the protective layer many technology firms have regarded as one of the strongest tools against digital intrusions. Google's disclosure suggests that an advanced AI system can identify attack paths that defeat traditional security mechanisms.
AI accelerates cyberattacks
Google and other experts say artificial intelligence has dramatically increased the speed of cyberattacks. Whereas previously there was typically a 60–90 day gap between the disclosure of a vulnerability and its mass exploitation, analysts now speak in terms of minutes or hours. Attackers are automating vulnerability discovery, malicious code development, and even the orchestration of entire attack chains with AI systems.
The UK-based Artificial Intelligence Safety Institute (AISI) has warned that next-generation AI models may be capable of carrying out autonomous cyberattacks. After testing a system called Mythos, the institute concluded the program exhibited dangerously advanced capabilities and therefore did not release it publicly. The AISI also reported that the ChatGPT 5.5 model demonstrated similar levels of performance in cybersecurity tests.
Consequences: an arms race and rethinking defenses
A senior analyst at Google pointed out that if criminal groups already use such technologies, state-sponsored hacking collectives may employ even more advanced systems. This dynamic is only partially visible now and effectively marks the beginning of a competition in which AI will be both an offensive and defensive weapon.
This is an acute problem for the technology sector because two-factor authentication has been widely promoted in recent years as a near-universal solution against digital threats. The recent incident shows that even that layer can be circumvented by sufficiently advanced AI-driven attack techniques.
At the same time, Google and other major tech companies emphasize that AI itself could become part of the solution. In the future, artificial intelligence could analyze software before release and automatically detect potential bugs and vulnerabilities. The challenge is that many systems in use today are older and may contain numerous unpatched or undiscovered security gaps.
As a result, the cybersecurity market is increasingly resembling a military-style contest: it is no longer just about IT defense but about an ongoing technological arms race in which AI plays a growing role on both sides. Google's warning underscores that traditional password rotation and two-factor authentication alone may no longer provide sufficient protection.
What this means for users and organizations
- Short-term risk mitigation should still include layered defenses, but modernization and rapid patching are essential.
- Long-term strategies may need to adopt AI-based security tools that detect and remediate bugs early and automatically.
- For critical systems, continuous risk assessment and fast remediation of discovered vulnerabilities are vital because AI enables much quicker exploit development.
The recent disclosure serves as a reminder that cybersecurity is not static: technological progress alters the capabilities of attackers and defenders alike, and organizations and policymakers must adapt accordingly.


