Security/ security · ai · zero-day · vulnerability

Google Confirms First AI-Discovered Zero-Day Deployed in the Wild

A criminal actor used a frontier AI model to find a 2FA bypass, build an exploit, and deploy it before any defender knew the flaw existed.

Google Confirms First AI-Discovered Zero-Day Deployed in the Wild

Google's Threat Intelligence Group has confirmed the first documented case of an AI model used to both discover and weaponize a zero-day exploit that was then deployed in a real attack.

In May, researchers documented a criminal actor who used a frontier AI model to identify a two-factor authentication bypass, build a working exploit, and use it before the vulnerability was known to exist. That end-to-end sequence, running from discovery through exploitation inside a single AI-assisted operation, is what separates this case from prior incidents. Previous AI-assisted attacks had humans making at least some of those calls independently. This one compressed the whole chain.

The structural problem is not subtle: the frontier models that security researchers use to scan codebases and surface vulnerabilities at scale are the same models that criminal and state actors want to replicate. A tool that accelerates defensive work accelerates offensive work too, and it does so asymmetrically. Defenders need to catch every flaw; attackers need one. The traditional patch cycle assumes a gap between discovery and exploitation. AI is closing that gap toward zero.

Geopolitical interest in copying these models is not background noise. If the same system that audits software at scale can also pivot to finding and weaponizing a specific zero-day before any patch exists, arguments about responsible access stop being theoretical and start being a race.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →