Google Spots First AI-Discovered Zero-Day Exploit

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Google's Threat Intelligence Group disclosed what it calls the first known instance of hackers using AI to discover and weaponize a zero-day vulnerability, covered by 20+ outlets including the New York Times, Reuters, and the AP.
- John Hultquist, TIG's chief analyst, said the discovery is 'the tip of the iceberg,' framing the finding as the start of a broader trend in AI-assisted exploits.
- The zero-day targeted a web admin tool, with The Register and BleepingComputer reporting that Google disrupted the planned mass cyberattack before attackers could deploy it.
- Coverage split across security outlets (CyberScoop, Security Affairs, BleepingComputer), tech press (The Verge, Engadget, SiliconANGLE), and general news (NYT, Reuters, AP, Politico), all reporting the same core finding.
- Common Dreams framed the disclosure as evidence that 'better AI oversight is urgently needed,' while Implicator.ai headlined it as 'AI Has Entered the Zero-Day Race.'
Why it matters: Google's TIG identified the first AI-developed zero-day while disrupting a planned mass cyberattack. With its chief analyst calling it 'the tip of the iceberg,' the disclosure gives defenders and regulators a concrete first case to work from — and the security press is treating it as a starting gun, not an isolated incident.
Ask SkimNews

