IC Technology & Surveillance — 2026-05-13

Google Detects First AI-Developed Zero-Day Exploit Before Mass Deployment

Google's Threat Intelligence Group (GTIG) reported on May 11 that it detected a zero-day exploit built with AI and alerted the affected vendor before a cybercrime group could initiate a mass-exploitation campaign. The patched vulnerability resided in a Python script in a popular open-source web administration tool and enabled attackers to bypass two-factor authentication; Google declined to name the tool or the specific flaw. GTIG chief analyst John Hultquist told CyberScoop that artifacts in the exploit code, including documentation strings, annotated Python, and a hallucinated CVSS score, indicated heavy AI involvement. Google stated the model used was neither Gemini nor Anthropic's Mythos; GTIG said it has not determined whether AI also discovered the underlying vulnerability.

Analysis
Google's detection confirms AI has moved into the most demanding phase of offensive cyber operations: weaponizing unknown vulnerabilities at scale. The implicated group's record of mass exploitation indicates this is not an experimental capability but one integrated into mature threat operations. GTIG has not established whether AI also discovered the underlying flaw; if it did, the interval between a vulnerability's existence and its weaponized exploit would compress substantially. We assess it is genuinely uncertain whether at least one AI-developed zero-day will be successfully deployed in a mass cyberattack by end of 2027. Confidence in this assessment is moderate, resting on a single confirmed detection with no primary-source technical documentation and open questions about how far AI has penetrated the discovery phase of the exploit development cycle.
2 sources
  1. Google spotted an AI-developed zero-day before attackers could use it - CyberScoop
  2. Google Researchers Detect First AI-Built Zero-Day Exploit in Cyberattack - Bloomberg

View in full brief →

UNCLASSIFIED // OPEN SOURCE