Google Spots First AI-Discovered Zero-Day Exploit

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Google's Threat Intelligence Group (TIG) reported the first known instance of hackers using AI to discover and weaponize a zero-day vulnerability, disrupting the operation before exploitation
- TIG chief analyst John Hultquist warned "this is the tip of the iceberg" regarding AI-enabled cyberattacks, per the New York Times
- The zero-day targeted a web admin tool, and the hackers had planned a mass exploitation campaign that Google intercepted, according to BleepingComputer and The Register
- Coverage converged across the New York Times, Associated Press, The Verge, CyberScoop, and Politico, all framing the disclosure as a watershed moment in AI-enabled offensive hacking
- Google's own Keyword blog cast the finding as a defensive success, while watchdogs including Common Dreams and Public Citizen used the disclosure to argue AI oversight is urgently needed
- The discovery was tied to Google's broader threat report, with Hultquist posting a thread on X amplifying the findings to the security community
Why it matters: This is the first documented end-to-end case of AI being used to find and prepare an unknown vulnerability for mass exploitation, moving AI cyber risk from theoretical to observed. The disclosure hands defenders a concrete reference point — and gives regulators (Public Citizen, Common Days) fresh ammunition for oversight demands, while letting Google position itself as the entity that caught it.
Ask SkimNews

