Cybersecurity
Lab
May 12, 2026
Google Threat Intelligence Group — First AI-Generated Zero-Day Exploit

Google confirmed the first known case of cybercriminals using AI to discover and weaponize a zero-day vulnerability. They planned a mass exploitation event.

“For the first time, GTIG has identified a threat actor using a zero-day exploit that we believe was developed with AI. The criminal threat actor planned to use it in a mass exploitation event but our proactive counter discovery may have prevented its use.” — Google Threat Intelligence Group

Google’s Threat Intelligence Group reported that multiple cybercrime threat actors collaborated to use AI to identify a bug in a Python script that would let them bypass two-factor authentication on a widely used open-source system. The groups then used AI-assisted code to weaponize the previously unknown vulnerability for planned mass exploitation. Google’s proactive discovery thwarted the attack before deployment. Separately, the report found that groups linked to China and North Korea demonstrated “significant interest in capitalizing on AI for vulnerability discovery.” This comes weeks after Anthropic delayed the rollout of its Mythos model citing concerns that criminals could use it to identify and exploit decades-old software vulnerabilities. The GTIG report represents a transition from theoretical risk to confirmed operational use of AI in offensive cyber operations.

1st
Confirmed AI-generated
zero-day exploit
2FA
Authentication bypass
was the target
Mass
Exploitation event
was planned
How AVAAS solves this

AI is now being used to discover vulnerabilities in the systems that other AI agents rely on. When cybercriminals use AI to find and weaponize zero-days in authentication systems, every AI agent that depends on those systems inherits that exposure. AVAAS sealed deployment verification detects changes to the authentication and infrastructure layers your AI depends on. An agent running on a compromised authentication system does not pass certification. This finding also reinforces the AISI cyber capability timeline: the doubling time for AI cyber capabilities has accelerated to 4.7 months. Independent verification of the full deployment stack, not just the model, is how enterprises stay ahead of that curve.

✓ Verified
Google Threat Intelligence Group (May 12, 2026). Google Cloud Blog. Covered by: Axios, Bloomberg, CNBC

This entry is one of 37 documented cases in the AVAAS evidence ledger, a public record of AI and automated-system failures with a verified source on every entry.

Every case here reached a person.

AVAAS certifies how AI systems behave at the decision point, with documented third-party evidence of conformity to a published standard.

Certify Your AI →