WorkThe story, in brief

Google stopped a zero-day hack that it says was developed with AI

For the first time, Google detected a zero-day exploit built with AI. Here's what that means for your security posture.

Illustration of two anonymous hands arranging task cards around an amber tool on a shared desk.
People, judgement and the changing nature of work.AI illustration by KeyNews
The KeyNews take

Why it matters

AI-assisted cybercrime is moving from theory to operational reality. This is the first documented case of threat actors using LLMs to develop exploits at scale, signaling a fundamental shift in attack surface management that every CTO needs to plan for.

The key facts

6 to know
  1. First documented zero-day exploit developed with AI assistance

  2. Exploit targeted 2FA bypass on open-source web admin tool

  3. Threat actors planned 'mass exploitation event'

  4. Google identified AI involvement through hallucinated CVSS scores and LLM-consistent formatting in Python script

  5. Detected by Google Threat Intelligence Group

  6. Published May 11, 2026

Go to the source

The Verge AItheverge.com

Publisher excerpt: For the first time, Google says it has spotted and stopped a zero-day exploit developed with AI. According to a report from Google Threat Intelligence Group (GTIG), "prominent cyber crime threat actors" were planning to use the vulnerability for a "mass exploitation event" that would have allowed…
Read original report
Back to today's editionMore work news

Keep reading

Related stories

More from Work