Cybersecurity — 2026-05-11

Google Detects First AI-Generated Zero-Day Exploit Used in the Wild

In a report published Monday, Google said a cybercrime group used an AI model to develop a zero-day exploit targeting two-factor authentication in an unnamed open-source web administration tool. Google attributed AI authorship to structural features of the Python exploit script, including educational docstrings, a hallucinated CVSS score, and textbook Pythonic formatting, while stating it does not believe Gemini was the AI used. The company said it coordinated with the affected vendor to prevent what it described as a planned mass-exploitation campaign. The same report identified a China-linked actor deploying tools including Strix and Hexstrike against targets in Japan and East Asia, and North Korean group APT45 using AI to recursively analyze CVEs and validate proof-of-concept exploits.

Analysis
Per a single Google threat intelligence document with no independent corroboration, behavioral fingerprints in the exploit script, including hallucinated CVSS scores, educational docstrings, and Pythonic formatting, indicate AI was embedded throughout scripting rather than used as a supplementary research aid, compressing time between vulnerability discovery and operational deployment. APT45's recursive CVE enumeration and UNC2814's persona-driven jailbreaks confirm AI integration across the exploitation pipeline is broad and multi-actor rather than episodic. Those artifacts are equally consistent with a developer using an AI coding assistant, which would overstate AI agency. A second confirmed AI-generated zero-day surfacing by 11 November 2026 is a roughly even chance, with adversary sanitization of AI artifacts and limited visibility into unreported campaigns as the binding variables.
5 sources
  1. Google Detects First AI-Generated Zero-Day Exploit Used in the Wild - Cyber Security News
  2. Google Researchers Detect First AI-Built Zero-Day Exploit in Cyberattack - Bloomberg
  3. Google Detects First AI-Generated Zero-Day Exploit - SecurityWeek
  4. Google says criminals used AI-built zero-day in planned mass hack spree - The Register
  5. Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - Google Threat Intelligence Group

View in full brief →

UNCLASSIFIED // OPEN SOURCE