‘This is the tip of the iceberg’: Google experts say they’ve seen hackers use AI to discover and weaponize a zero-day for the first time



  • GTIG detected threat actors using AI to identify and exploit a zero-day
  • Vulnerability allowed two-factor authentication to be bypassed
  • AI is able to “read” the developer’s intent and can “see” how hardcoded exceptions relate to security enforcement.

Threat actors are leveraging AI at a new scale, marking a shift from small-scale AI-assisted attacks to “industrial-scale” attacks, including using AI to discover and exploit a zero-day, the first recorded case of its kind.

These are the findings of Google Threat Intelligence Group’s AI Threat Tracker, which explores how threat actors leverage AI in attacks.

Leave a Comment

Your email address will not be published. Required fields are marked *