Google's TIG reports the first known example of hackers using AI to discover and weaponize a zero-day; TIG's chief analyst says “this is the tip of the iceberg”
The company said that it had identified, for the first time, hackers using artificial intelligence to discover an unknown bug.
New York TimesDustin Volz
Context & Ripple Effects
Google’s threat researchers had already documented a rise in exploited zero-days in 2025, with commercial spyware providers and China-linked groups among the leading sources of abuse. The related reporting now adds AI-assisted discovery and weaponization to that existing exploitation problem.
A companion report says TIG likely stopped an AI-generated zero-day before a potential mass-exploitation event, while tools such as OpenClaw are being used to search for exploits. That makes this less about a theoretical capability than about its appearance in an active defensive incident.
First-order effects
Google and other defenders must treat AI-assisted vulnerability research as an operational threat model, not merely a future risk, and accelerate detection, patching, and investigation around newly found flaws.
Attackers able to use AI in exploit discovery can potentially shorten the interval between a bug’s discovery and attempted weaponization, raising urgency for affected software vendors and their customers.
Second-order effects
Security teams and vulnerability-research vendors will face pressure to deploy comparable AI-assisted code analysis and triage, while improving controls that distinguish legitimate research from exploit-development activity.
The prior concentration of zero-day abuse among spyware vendors and China-linked groups suggests that better AI-enabled discovery could amplify capabilities already used by well-resourced actors, increasing demand for faster coordinated disclosure and patch adoption.
Third-order effects
If AI materially compresses zero-day discovery and weaponization cycles, the security industry may shift further from periodic patching toward continuous code assessment, rapid mitigation, and exploit-focused monitoring.
The same dual-use tools that can help defenders find flaws will intensify debate over model safeguards and access controls; the evidence here establishes an early real-world case, not yet the scale or persistence of the broader effect.
The trend: This is an early signal that generative AI is moving from a security-research aid into a dual-use capability that could accelerate the zero-day arms race between attackers and defenders.
I'm sure people will want more details on this specific incident, and we have good reasons for not sharing all of the data, but I'd challenge you to focus on the bigger picture. If criminals are doing it, then state actors with significant resources probably are too. 4/x
Google Threat Intelligence Group is dropping our latest AI Threat Tracker report today, which covers several threats we are watching through a variety of means. The report includes some details of the first 0day exploit we've found developed with AI. 1/x https://cloud.google.com/…
Our regular reporting on AI threats is a landscape view, a pulse check on how adversaries are using and attacking AI. There are examples, but try not to get fixated on the specifics and instead look at the macro trends. Baddies love AI, as both a weapon and a target.
well-orchestrated ai will certainly scale + speed things up...but don't let stories hyping the “tip of the spear”™️ move your focus away from mastering 🅻🅴 🅱🅰🆂🅸🅲🆂. [image]
Aside from the sizzle of threat actors using AI to discover and exploit vulnerabilities, here is the substance that I'm most worried about longer term: [screenshot: “Beyond basic chat interfaces, we see a sophisticated shift toward agentic workflows where adversaries operationali…
it's crazy how much claude mythos has spooked DC, and perhaps changed the course of American AI regulation. there's been some speculation that mythos was released in a limited way because of Anthropic's compute constraints. If that's the case (frankly, I can't say one way or ano…
The AI-generated script had clear signs it was made with an LLM: • Lots of detailed explanations and comments • A made-up CVSS score • Professional-looking help menus and colors The flaw was a simple logic mistake in the software's code — a “trust assumption” that shouldn't
Each new generation of models will reduce the need for expert-developed harnesses, but they are almost certainly out there. We have to recognize the limits of our visibility into the backend of spies and criminals. The signs won't be obvious. The race has started already. 5/x
What's more, I think most of us are surprised we have not found more evidence. We believe this is the tip of the iceberg. Other AI-developed 0days are probably out there. At Google, BigSleep was a wake up call (2 years ago), but the threat grew with each generation of model. 3/x
A criminal threat actor was planning to use the 0day exploit, which has artifacts of AI development, in a mass exploitation event before it was patched. Frankly, the details of this event are not as important as the evidence that the era of adversary use is here. 2/x