Google finds AI-made zero-day exploit bypassing 2FA
Google found the first AI-made zero-day exploit bypassing 2FA in a web tool. The threat was neutralized before mass abuse. China- and North Korea-linked groups are exploring similar AI-driven attacks.
Google has uncovered the first zero-day exploit developed with the assistance of artificial intelligence, targeting two-factor authentication (2FA) in a widely used open-source web management tool. This discovery, made by the Google Threat Intelligence Group (GTIG), signals a significant shift in the cybersecurity landscape. Cybercriminals and state-sponsored actors are now leveraging AI models to speed up vulnerability research and exploitation. The exploit, written in Python, displayed hallmarks of AI-generated code, including educational docstrings and fabricated CVSS scores. Google collaborated with the affected vendor to patch the vulnerability before it could be exploited at scale. The report also notes ongoing interest from groups associated with China and North Korea in using AI for exploit development and automating cyberattack campaigns.