Back to Insights AI Security

Google cybersecurity researchers have identified zero-day exploits created with the assistance of AI.

Table of Contents

Has the Era of AI Attacks Already Begun? Google Unveils the First Zero-Day Created with Artificial Intelligence

Researchers from the Google Threat Intelligence Group (GTIG) have uncovered the first-of-its-kind case of a Zero-Day vulnerability created with the help of AI and identified within a real-world attack. According to the report, a threat actor used an AI model to identify a complex logical security flaw in an open-source web-based system—and even wrote a functional Python exploit for it that allowed bypassing a Two-Factor Authentication (2FA) mechanism.

The researchers note that while there has been evidence of attackers using AI for vulnerability research until now, this is one of the first cases where clear signs were found that AI was also involved in creating the exploit itself.

No More Just Classic Vulnerabilities – Complex Logical Flaws: Why Google Researchers Believe Models Already “Understand” Systems

According to GTIG, the vulnerability found was not a simple memory corruption or input sanitization bug, but a logical flaw resulting from incorrect trust assumptions embedded in the code. Researchers explain that advanced AI models are beginning to demonstrate contextual reasoning capabilities—meaning they can identify contradictions and faulty logic within the authorization architecture itself.

In this case, the AI successfully understood how the 2FA mechanism conflicted with hardcoded exceptions written in the code, thereby exposing a bypass path that traditional scanners failed to detect. It was further noted that the exploit code contained characteristics identified with code generation via Large Language Models (LLMs), including “educational” commentary, unnecessary help menus, and even a fabricated CVSS score.

AI is Becoming Part of the Cyber Attack Lifecycle: From Google Gemini to Autonomous Agentic AI Tools

The report states that threat actors are currently using AI not only for finding vulnerabilities but also for writing malware, obfuscation, attack automation, creating deepfakes, and managing entire attack processes. According to the researchers, Chinese and North Korean groups have attempted to bypass Gemini’s guardrails using dedicated prompt engineering to analyze TP-Link device firmware, identify vulnerabilities, and improve existing exploits.

Additionally, attackers are using “Agentic AI” tools such as OpenClaw and OneClaw to conduct vulnerability research in dedicated test environments, and are even feeding models information gathered from tens of thousands of real-world vulnerability cases to improve the quality of the payloads and exploits they produce.

Recommendations from IPV Security Professionals: Preparing for an Era Where AI Generates Attacks Rather Than Just Assisting Them

  • Strengthen controls around authorization mechanisms and 2FA.
  • Conduct code reviews focused on logical failures, not just classic vulnerabilities.
  • Monitor for anomalous use of AI and prompt engineering within the organization.
  • Integrate AI security defenses and threat modeling into development processes.

Conclusion

The line between a human attacker and AI is beginning to blur. GTIG’s disclosure marks a significant shift in the cyber landscape: Artificial Intelligence is no longer just a supporting tool for attackers—it is an active player in the attack chain itself. When models can understand business logic, identify contradictions in code, and create autonomous exploits, organizations must prepare for a new reality where attacks become much faster, smarter, and more automated.

For further information:
https://www.csoonline.com/article/4169046/google-discovers-weaponized-zero-day-exploits-created-with-ai.html

Interested in performing infrastructure or application penetration testing? Contact the experts at IPV Security!

For professional consultation, you can reach us at info@ipvsecurity.com or by phone at 077-4447130. IPV Security has specialized for 21 years in information security, cyber operations, risk assessments, and standards and regulations regarding data security.

Continue the Conversation

Facing a cybersecurity challenge? Let's talk about how a managed program can strengthen your resilience.

Start a conversation