Google Halts AI‑Generated Zero‑Day Attack

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Google Threat Intelligence Group discovered the AI‑linked zero‑day exploit and disrupted it before a mass‑exploitation event could occur.
- The exploit targeted an unnamed open‑source, web‑based system administration tool and could bypass its two‑factor authentication.
- The exploit code contained a hallucinated CVSS score and textbook‑style formatting, indicating it was likely generated with a large language model.
- Hackers are employing persona‑driven jailbreaking prompts and feeding AI models whole vulnerability repositories to refine payloads, using tools such as OpenClaw.
- Google says its researchers do not believe the Gemini model was used in creating the exploit.
- Attackers are increasingly targeting integrated AI components like autonomous skills and third‑party data connectors.
Why it matters: Defenders gain a rare glimpse of AI‑enabled weaponization, while attackers lose a planned breach; the incident proves AI can generate functional exploits, prompting security teams to treat AI‑generated code as a higher‑risk threat vector. It also underscores the need for AI‑aware defenses and signals that AI‑driven attacks may become more common, affecting enterprises that rely on open‑source admin tools.

