What Happened With the AI-Developed Zero-Day?
Google’s Threat Intelligence Group (GTIG) found evidence in the exploit’s Python code that an AI model was used to find and weaponize the vulnerability. Signs included “hallucinated” CVSS scores and “structured, textbook” formatting consistent with LLM training data. The exploit targeted a high-level semantic logic flaw where a developer had hardcoded a trust assumption into a 2FA system.
How Did Google Detect the Threat?
Google DeepMind and Project Zero’s Big Sleep agent — an AI system designed to search for unknown security vulnerabilities — found the flaw before the criminal group could exploit it. Google also introduced CodeMender, an AI agent that uses Gemini’s reasoning capabilities to automatically fix critical code vulnerabilities. The defensive AI found the flaw before the offensive AI could weaponize it in production.
What Does This Mean for the Future of Cybersecurity?
The incident marks a threshold: AI vulnerability discovery has crossed from research curiosity into operational reality. The GTIG report documents state-sponsored actors from China, North Korea, and Russia using AI for vulnerability research, autonomous malware using commercial AI APIs, and supply chain attacks targeting the AI software ecosystem.