Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    More Lenovo Legion Y70 2026 specs revealed ahead of launch

    May 13, 2026

    Lenovo’s new ThinkPad and ThinkStation PCs look better than ever

    May 13, 2026

    Galaxy Z Fold 8 and Flip 8 could launch with Gemini Intelligence

    May 13, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Google Detects First AI-Generated Zero-Day Exploit
    Google Detects First AI-Generated Zero-Day Exploit
    Cybersecurity

    Google Detects First AI-Generated Zero-Day Exploit

    The Tech GuyBy The Tech GuyMay 12, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    For the first time, Google has identified a zero-day exploit believed to have been developed using artificial intelligence.

    Advertisement

    The company published a new report on Monday summarizing its observations on the use of AI in the cyber threat landscape, drawing on data collected recently by Gemini, Google Threat Intelligence Group (GTIG), and Mandiant. 

    One of the most notable findings is that a prominent cybercrime group leveraged AI to develop a zero-day exploit designed to bypass two-factor authentication (2FA) on an open source web-based system administration tool. The exploit was implemented in a Python script.

    The hacker group and the targeted tool have not been named, but Google said it worked with the impacted vendor to prevent mass exploitation, which appeared to be the threat actor’s plan.

    “Although we do not believe Gemini was used, based on the structure and content of these exploits, we have high confidence that the actor likely leveraged an AI model to support the discovery and weaponization of this vulnerability,” Google explained. 

    It added, “For example, the script contains an abundance of educational docstrings, including a hallucinated CVSS score, and uses a structured, textbook Pythonic format highly characteristic of LLMs training data (e.g., detailed help menus and the clean _C ANSI color class).”

    Advertisement. Scroll to continue reading.

    Google highlighted that Chinese and North Korean state-sponsored threat actors have been particularly interested in leveraging AI for vulnerability discovery. 

    A China-linked actor was observed deploying agentic tools such as Strix and Hexstrike in attacks targeting a Japanese tech firm and a major East Asian cybersecurity company. 

    UNC2814, a Chinese group known for targeting telecoms and government organizations, used a persona-driven jailbreak — in which the AI is instructed to act as a senior security auditor — to enhance vulnerability research on embedded devices, including TP-Link firmware with OFTP implementations. 

    According to Google, the North Korean group tracked as APT45 sent out thousands of repetitive prompts to recursively analyze CVEs and validate PoC exploits.

    “This results in a more robust arsenal of exploit capabilities that would be impractical to manage without AI assistance,” Google said in its report. 

    The full report also covers autonomous malware operations, AI-augmented defense evasion, supply chain attacks, and threat actors pursuing premium access to LLMs.

    Related: Google: Half of 2025’s 90 Exploited Zero-Days Aimed at Enterprises

    Related: Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google

    Related: Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Exaforce Raises $125 Million for Agentic SOC Platform

    May 13, 2026

    Microsoft Patches 137 Vulnerabilities – SecurityWeek

    May 12, 2026

    Adobe Patches 52 Vulnerabilities in 10 Products

    May 12, 2026

    TanStack, Mistral AI, UiPath Hit in Fresh Supply Chain Attack

    May 12, 2026

    Frame Security Emerges From Stealth With $50M for Awareness and Training Platform

    May 11, 2026

    Build Application Firewalls Aim to Stop the Next Supply Chain Attack

    May 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20258 Views

    Facebook updates its algorithm to give users more control over which videos they see

    October 8, 20258 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    More Lenovo Legion Y70 2026 specs revealed ahead of launch

    May 13, 2026

    Lenovo’s new ThinkPad and ThinkStation PCs look better than ever

    May 13, 2026

    Galaxy Z Fold 8 and Flip 8 could launch with Gemini Intelligence

    May 13, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.