Google says criminals used AI to build a working zero-day exploit for the first time
First confirmed zero-day built entirely by AI. Google's threat intelligence team just documented criminals weaponizing LLMs at scale.

Why it matters
This marks a critical inflection point in AI security risk: criminal actors have moved from AI-assisted to AI-native exploit development. For security leaders and AI governance teams, this validates worst-case threat models and should reshape vulnerability disclosure and model safety policies.
The key facts
5 to knowFirst confirmed case of AI-generated working zero-day exploit
Criminal group used AI to build Python-based exploit
Exploit targeted two-factor authentication bypass
Source: Google Threat Intelligence Group AI Threat Tracker report
Published May 11, 2026
Go to the source
SiliconAnglesiliconangle.com
Publisher excerpt: Criminal hackers have used artificial intelligence to develop a working zero-day exploit, the first confirmed case of its kind, according to a report released today by Google LLC’s Google Threat Intelligence Group. The GTIG AI Threat Tracker report details how a criminal group used AI to build a…