Wednesday, July 22, 2026
TechnologyBREAKING

First AI-Developed Zero-Day Exploit Emerges Amid Rising Cybersecurity Threats

Google identifies the first zero-day exploit developed with AI, raising alarms in cybersecurity.

PM

Paolo Mendoza

May 13, 20266 min read111 views
First AI-Developed Zero-Day Exploit Emerges Amid Rising Cybersecurity Threats
A visual representation of AI's role in cybersecurity, highlighting emerging threats.
Share:

At the end of 2025, researchers made a startling discovery: common AI tools used for productivity are now being exploited for cyberattacks. These tools have lowered the skill barrier for cybercriminals, enabling them to craft sophisticated phishing emails and write harmful code.

On May 12, Google’s Threat Intelligence Group (GTIG) released a report detailing key developments in AI-assisted cyber threats. Among the findings was the identification of a zero-day exploit, marking the first instance of such an exploit being developed with AI.

A zero-day exploit refers to a previously unknown vulnerability that attackers can exploit before it is patched. GTIG's report indicated that the identified exploit could allow attackers to bypass two-factor authentication on a widely used open-source web administration tool.

GTIG noted that major cyber threat actors were collaborating to exploit this vulnerability. However, the group worked with the affected vendor to disclose the exploit and mitigate the potential attack.

For the first time, GTIG has identified a threat actor using a zero-day exploit that we believe was developed with AI.

Google Threat Intelligence Group

The report also highlighted that threat actors from China and North Korea are increasingly interested in utilizing AI for vulnerability discovery. One tactic involved training a large language model (LLM) with a database of 85,000 real-world vulnerability cases.

This training allowed the model to perform code analysis more effectively, identifying flaws akin to a seasoned expert. GTIG observed a notable trend toward automation in cyberattacks, with agentic AI enabling attackers to manage various tasks without human intervention.

In an analysis of an attack against a Japanese tech firm, GTIG found that the threat actor employed tools that automated vulnerability identification and validation, creating a larger attack surface with reduced human oversight.

GTIG emphasized that the LLM has transitioned from being a passive advisor to an active participant in cyber offensives, capable of orchestrating complex attacks at machine speed.

Despite these concerning developments, cybersecurity firms maintain that AI can also enhance defenses. At a recent cybersecurity briefing, Fortinet reported that AI-driven threats have become a top concern for organizations in the Asia-Pacific region.

The survey revealed that 57% of Philippine cybersecurity leaders now view AI threats as their primary concern, a significant rise in just five months. One challenge highlighted was 'tool fragmentation,' where organizations rely on numerous disconnected security tools.

Fortinet also pointed out the ongoing cybersecurity skills gap, with companies struggling to find professionals with expertise in AI security. The rise of 'shadow AI'—where employees use AI tools without IT oversight—has further complicated the issue.

In response, many organizations plan to increase cybersecurity budgets, particularly for AI-enabled tools and workforce training. Over 60% of surveyed firms expect AI to improve detection accuracy and accelerate response times.

Experts recommend a 'humans on the loop' approach, where AI systems handle specific tasks while human analysts oversee critical decisions. Fortinet's country manager emphasized that human judgment remains essential in cybersecurity.

The bad guys work together, the good guys need to work together as well...We need an ecosystem approach to cybersecurity.

Rashish Pandey, Fortinet