Cybersecurity Policy Report, Google Reports ‘First’ Case of Hackers Using AI to Find ‘Zero-Day’ Vulnerability, (May 11, 2026)
Hackers using AI (artificial intelligence) identified a “zero-day” cyber vulnerability and planned to use it for “a mass vulnerability exploitation operation,” Google LLC’s Threat Intelligence Group (GTIG) disclosed today.
“For the first time, GTIG has identified a threat actor using a zero-day exploit that we believe was developed with AI. The criminal threat actor planned to use it in a mass exploitation event but our proactive counter discovery may have prevented its use,” GTIG said in a report.
New AI models have proven adept at scanning software and finding zero day vulnerabilities—previously unknown flaws that have no immediate fix. The example discovered by GTIG involved “prominent cyber crime threat actors” and a vulnerability that would have allowed them “to bypass two-factor authentication (2FA) on a popular open-source, web-based system administration tool,” GTIG said.
GTIG said it “worked with the impacted vendor to responsibly disclose this vulnerability and disrupt this threat activity.”
The hackers didn’t use Google’s Gemini AI model in their planning, GTIG assessed, but based on “the structure and content of these exploits, we have high confidence that the actor likely leveraged an AI model to support the discovery and weaponization of this vulnerability.”
While the use of AI to discover and exploit vulnerabilities remains unusual, GTIG said hackers were employing large language models (LLMs) for the same purposes as “standard users”—to “conduct research and troubleshoot tasks.”
“Adversaries frequently use LLMs to perform reconnaissance that would previously have required significant manual effort. For instance, we have observed actors prompting models to generate detailed organizational hierarchies for specific departments and third-party relationships of large enterprises, particularly those involving high-value functions like finance, internal security, and human resources,” it said.
“This data allows for the creation of higher-fidelity phishing lures tailored to individuals with administrative privileges or access to sensitive data, moving beyond the commodity tactics of traditional bulk phishing,” GTIG added. “By automating intelligence gathering and task support, these interactions lower the barrier to entry for complex, multi-stage operations.”
News: InternationalLegislation DataSecurity AINews