Chronicle/Attacks & incidents

Google Threat Intelligence reports the first criminal zero-day exploit it believes was AI-developed, disrupted before planned mass use

AttackMisuse reportSignificance assistant-drafted

Google Threat Intelligence Group reported that cybercriminals planned a mass-exploitation campaign using a two-factor-authentication bypass in an open-source web administration tool, and assessed with high confidence that an AI model supported discovery and weaponization of the flaw. GTIG worked with the vendor on disclosure and disrupted the activity. The same report describes PRC-nexus actors using agentic frameworks such as Hexstrike and Strix for reconnaissance and vulnerability validation, and Android malware (PROMPTSPY) that calls Gemini to drive the device UI.

Why it matters

GTIG calls it the first identified instance of a zero-day exploit it believes was AI-developed by cybercrime actors.

Key facts

As stated in the sources, with where to find them.

  • GTIG assessed with high confidence that an AI model supported discovery and weaponization of a 2FA-bypass logic flaw; it states it does not believe Gemini was used.AI-developed zero-day section
  • A suspected PRC-nexus actor used Hexstrike (with a knowledge-graph memory) and the Strix multi-agent pentest framework against a Japanese technology firm and an East Asian security platform.Hexstrike and Strix section
  • UNC6780 (TeamPCP) supply-chain compromises touched repositories including LiteLLM, Trivy and Checkmarx.Supply chain section

Findings that cite this record

Key questions this bears on

Sources

Related records