Google stopped a zero-day hack that it says was developed with AI
For the first time, Google detected a zero-day exploit built with AI. Here's what that means for your security posture.

Why it matters
AI-assisted cybercrime is moving from theory to operational reality. This is the first documented case of threat actors using LLMs to develop exploits at scale, signaling a fundamental shift in attack surface management that every CTO needs to plan for.
The key facts
6 to knowFirst documented zero-day exploit developed with AI assistance
Exploit targeted 2FA bypass on open-source web admin tool
Threat actors planned 'mass exploitation event'
Google identified AI involvement through hallucinated CVSS scores and LLM-consistent formatting in Python script
Detected by Google Threat Intelligence Group
Published May 11, 2026
Go to the source
The Verge AItheverge.com
Publisher excerpt: For the first time, Google says it has spotted and stopped a zero-day exploit developed with AI. According to a report from Google Threat Intelligence Group (GTIG), "prominent cyber crime threat actors" were planning to use the vulnerability for a "mass exploitation event" that would have allowed…