agent-postmortems a structured database of real AI-agent failures

← all incidents

incident high confidence: confirmed status: factual

Google GTIG reported the first real-world case of criminals using AI to discover and weaponize a zero-day

2026-gtig-ai-developed-zeroday · 2026-05-11

Google's Threat Intelligence Group documented what it assessed as the first real-world case of a criminal operation using an AI model to both discover a zero-day vulnerability — a two-factor-authentication bypass in a popular open-source web administration platform — and help turn it into a working exploit for a planned mass-exploitation campaign. Google worked with the vendor to patch it before the campaign gained traction.

System

Framework
AI model used by a criminal operation for vulnerability discovery and exploit development
Vendor
unattributed criminal operators
Autonomy
unknown

Classification

Primary class
autonomous-misuse
Chain
autonomous-misuse/cyber-ops
Attack vector
n-a
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

Operators planning a large-scale intrusion campaign used an AI model to identify a two-factor-authentication bypass in a widely used open-source web-based administration platform and to help develop it into a usable exploit.

Root cause

General AI capability for code and vulnerability analysis was applied to offensive ends — discovering and weaponizing a previously unknown flaw — lowering the effort required to produce a working zero-day exploit at scale.

Contributing factors

  • AI models can accelerate vulnerability discovery and exploit development for capable operators.
  • A widely deployed open-source platform provided a high-value mass-exploitation target.
  • Related activity was observed (North Korean APT45 using AI for bulk exploit checks; state-linked operators experimenting with AI vulnerability hunting).

Detection

Identified and reported by Google's Threat Intelligence Group (GTIG) on 2026-05-11; Google stated neither Gemini nor Anthropic's Mythos was involved.

Recovery

Google worked with the affected vendor to quietly patch the vulnerability before the campaign could properly begin, which it assessed as disrupting the operation.

Prevention

Treat AI-accelerated vulnerability discovery as part of the threat model; prioritise rapid patching of widely used platforms; enforce provider usage policies and abuse detection against offensive-security misuse of AI models.

Blast radius

Data
A weaponized zero-day (a 2FA bypass) developed with AI assistance for a planned mass-exploitation campaign against a widely used open-source administration platform. n-a
User harm
The campaign was disrupted by an early patch before widespread exploitation was reported. none-reported
Scope
a widely used open-source web administration platform (planned mass exploitation)
Reversibility
reversible

References

Tags
autonomous-misuse zero-day ai-exploit-development offensive-ai first-of-kind

Sources

Cite this incident

@misc{2026-gtig-ai-developed-zeroday,
  title = {Google GTIG reported the first real-world case of criminals using AI to discover and weaponize a zero-day},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-gtig-ai-developed-zeroday/}
}