Google says it stopped a mass cyberattack after AI was used to discover a zero-day exploit
First confirmed case: AI-discovered zero-day weaponized in mass attack. Google stopped it—but state actors are already doing the same.

Why it matters
AI is moving from a competitive advantage to a national security threat. Adversaries are using large language models to automate vulnerability discovery at scale, forcing enterprise security teams to rethink their defensive posture entirely.
The key facts
6 to knowFirst known case of attacker using AI to discover and weaponize zero-day exploit
Google Threat Intelligence Group identified the attack
Mass attack was stopped before deployment
State-backed actors from China, North Korea, and Russia confirmed using AI for vulnerability discovery
AI also being used to disguise malware code
Published May 12, 2026
Go to the source
The Decoderthe-decoder.com
Publisher excerpt: Google's Threat Intelligence Group has identified the first known case of an attacker using AI to discover and weaponize a zero-day vulnerability. Google says it stopped the planned mass attack. State-backed actors from China, North Korea, and Russia are also using AI to find vulnerabilities and…