Google reveals the first AI-generated zero-day vulnerability: hackers aim to bypass 2FA for large-scale exploitation

ChainNewsAbmedia

Google Threat Intelligence Group (GTIG) revealed on May 11 its first zero-day exploitation case “assisted by an AI model” on the wild: a hacker group planned to launch “large-scale exploitation” against a widely used open-source web-based system administration tool, with the goal of bypassing that tool’s two-factor authentication (2FA) login mechanism. Per a CNBC report, Google coordinated with the tool’s vendor to complete the vulnerability patching before the attack went live.

The incident itself: how zero-day vulnerabilities were “manufactured” by AI

After analyzing the Python exploit script left behind by the hackers, GTIG was “highly confident” the script was generated with help from an AI model. The determination was based on multiple LLM-typical tells found in the script:

A large number of tutorial-style docstrings and comments (unlike the usually concise code style of real hackers)

It contains “hallucination-style CVSS scores” (a common fabrication behavior of AI models)

A structured, textbook-like Python programming style with a detailed explanation menu

Clean template traces such as _C ANSI color classes that are “typical” of LLM training data

The vulnerability itself is a “high-level semantic logic flaw,” originating from a hard-coded trust assumption. Google described this as the type of vulnerability that LLMs are best at uncovering in code analysis. The real attack path: after obtaining the victim’s legitimate account credentials, the hackers bypass 2FA directly through the flaw.

Google’s response: silent patching with the vendor; the attack was not formally launched

Google did not disclose the name of the targeted open-source system administration tool, nor did it name the AI model vendor. After finding it, GTIG coordinated with the tool’s maintenance vendor to carry out a “responsible disclosure” process, silently patched the vulnerability, and Google assessed that this handling likely disrupted the momentum before the hacker group could formally launch large-scale exploitation.

Google also did not explicitly name the attacker—only described them as “cybercrime threat actors,” without identifying whether they have ties to nation-state actors.

Industry significance: AI x cybersecurity enters a new stage

Media observation: This case is the first publicly recorded instance by Google of “AI models being weaponized in the wild for vulnerability discovery and generation of exploitation code.” In the past six months, market discussion has debated whether “AI hacker capabilities are being exaggerated,” with both sides making arguments: the proponents say that open-source LLMs plus a dedicated dataset are enough to help find vulnerabilities, while the skeptics argue that exploit code written by LLMs usually cannot work in real environments.

GTIG’s assessment provides a concrete data point—LLMs can not only find vulnerabilities, but also write “operational” code sufficient to enable large-scale exploitation. Ryan Dewhurst, a cybersecurity researcher, commented: “AI has accelerated vulnerability discovery, reduced the effort needed to identify, validate, and weaponize flaws.”

Events that can be tracked next include: whether Google will continue to publicly release more AI-assisted hacker cases, whether other cybersecurity vendors (Microsoft Defender, CrowdStrike, Mandiant, etc.) will make similar observations, and whether LLM vendors (OpenAI, Anthropic, Google’s own) will build stricter detection mechanisms for vulnerability-analysis-type requests.

This Google article revealing the first case of AI-created zero-day vulnerabilities: hackers want to bypass 2FA for large-scale exploitation first appeared on ChainNews ABMedia.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Equinix to Invest $190M in AI-Ready Data Center in Malaysia

According to Equinix, the company plans to invest more than $190 million to build a new data center in Malaysia as demand for AI and cloud infrastructure rises. The facility, named KL2, will be constructed near Equinix's existing KL1 site in Cyberjaya and is designed to support AI, hybrid

GateNews24m ago

Cerebras IPO Drives Supply Chain Gains: Vicor’s Power Narrative and AI Power IP Licensing Theme

AI chip company Cerebras Systems (CBRS) IPO heat is rising. Not only has it drawn market attention to this wafer-scale AI chip company challenging NVIDIA, but some investors have also begun looking for “Cerebras theme stocks” and upstream supply-chain beneficiaries. Investment KOL Joe said on X recently that he believes Vicor (VICR) could play a similar role, becoming an indirect bet on Cerebras growth. Joe: From AAOI bets on Anthropic to using VICR to bet on Cerebras Cerebras has recently been

ChainNewsAbmedia29m ago

SoftBank Reports $1.5B Q1 Profit Lifted by $80B OpenAI Stake on May 13

According to Reuters, SoftBank Group is expected to report first-quarter net profit of 236 billion yen ($1.5 billion) on May 13, with gains from its OpenAI stake driving results. TD Cowen estimated SoftBank's 11% stake in OpenAI was worth $80 billion at the end of March, after the ChatGPT maker's

GateNews44m ago

South Korea Posts 6.4pp AI Adoption Jump to 37.1% in Q1 2026, Leads Global Rise

According to Microsoft's AI Economy Institute, South Korea's AI adoption rate rose 6.4 percentage points to 37.1% in the first quarter of 2026, posting the fastest increase globally. Asia accounted for 12 of the 15 fastest-growing markets. The UAE and Singapore remain the overall adoption leaders at

GateNews1h ago

Karpathy: AI shouldn’t stop at Markdown! HTML is the future; the endgame is explorative interactive scenarios

Karpathy on X responded to Shihipar, proposing a method of adding “Please present the answer in an HTML structure at the end of the prompt.” He believes that HTML can turn AI output from plain text into visible, interactive documents, surpassing Markdown, and discussed the future of replacing pure text with visual output, as well as the challenges of combining software engineering with diffusion models.

ChainNewsAbmedia1h ago
Comment
0/400
No comments