{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/gtig-ai-developed-zero-day-2026/",
 "asOf": "2026-09-26",
 "id": "gtig-ai-developed-zero-day-2026",
 "date": "2026-05-11",
 "datePrecision": "day",
 "title": "Google Threat Intelligence reports the first criminal zero-day exploit it believes was AI-developed, disrupted before planned mass use",
 "lane": "attack",
 "kind": "misuse-report",
 "summary": "Google Threat Intelligence Group reported that cybercriminals planned a mass-exploitation campaign using a two-factor-authentication bypass in an open-source web administration tool, and assessed with high confidence that an AI model supported discovery and weaponization of the flaw. GTIG worked with the vendor on disclosure and disrupted the activity. The same report describes PRC-nexus actors using agentic frameworks such as Hexstrike and Strix for reconnaissance and vulnerability validation, and Android malware (PROMPTSPY) that calls Gemini to drive the device UI.",
 "whyItMatters": "GTIG calls it the first identified instance of a zero-day exploit it believes was AI-developed by cybercrime actors.",
 "actors": [
  "google-threat-intelligence-group",
  "unc6780"
 ],
 "topics": [
  "ai-enabled-intrusion",
  "exploit-development",
  "ai-malware",
  "threat-intelligence"
 ],
 "atlas": [
  "model",
  "supply-chain"
 ],
 "artifacts": [
  "gemini"
 ],
 "sources": [
  {
   "url": "https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access",
   "publisher": "Google Cloud Blog (GTIG)",
   "title": "GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access",
   "date": "2026-05-11",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://cloud.google.com/security/resources/ai-risk-and-resilience-2026",
   "publisher": "Mandiant",
   "title": "AI Risk and Resilience: September 2026",
   "date": "2026-09",
   "type": "primary",
   "accessed": "2026-09-25",
   "shared": true
  }
 ],
 "keyFacts": [
  {
   "fact": "GTIG assessed with high confidence that an AI model supported discovery and weaponization of a 2FA-bypass logic flaw; it states it does not believe Gemini was used.",
   "locator": "AI-developed zero-day section"
  },
  {
   "fact": "A suspected PRC-nexus actor used Hexstrike (with a knowledge-graph memory) and the Strix multi-agent pentest framework against a Japanese technology firm and an East Asian security platform.",
   "locator": "Hexstrike and Strix section"
  },
  {
   "fact": "UNC6780 (TeamPCP) supply-chain compromises touched repositories including LiteLLM, Trivy and Checkmarx.",
   "locator": "Supply chain section"
  }
 ],
 "significance": 5,
 "fideQuestions": [],
 "methods": [
  "ai-assisted-exploitation",
  "malicious-agent-extensions"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}