Google's TIG says it likely thwarted the use of an AI-generated zero-day in a “mass exploitation event” and tools like OpenClaw are being used to find exploits
it's already here. — Today, the Threat Intelligence Group (GTIG) released our latest AI Threat Tracker …
Context & Ripple Effects
Google’s threat teams have previously tracked a persistently high volume of exploited zero-days: 75 in 2024 and 90 in 2025, with commercial spyware vendors and China-linked groups among the prominent sources of abuse in the related coverage.
This report adds AI-assisted vulnerability discovery and weaponization to that established zero-day problem. Its significance is not merely another exploit campaign, but evidence that AI tools are entering a stage of practical offensive use against real targets.
First-order effects
- Google’s Threat Intelligence Group’s reported intervention likely prevents or limits immediate harm from the identified mass-exploitation effort, while giving defenders concrete indicators and tactics to investigate.
- Attackers using tools such as OpenClaw can apply AI to exploit discovery, potentially shortening the path from finding a flaw to preparing it for use.
Second-order effects
- Security teams and software vendors face pressure to accelerate vulnerability triage, patch deployment, and detection engineering, because exploit research may become easier to operationalize.
- The report raises the value of threat-intelligence sharing around AI-assisted attack methods; defenders will need to distinguish routine AI-enabled research from activity tied to active exploitation.
Third-order effects
- If comparable cases recur, zero-day risk may increasingly be defined by the speed and scale of exploitation rather than only by the number of vulnerabilities discovered.
- The longer-term contest is likely to shift toward whether defenders can apply AI, telemetry, and coordinated disclosure quickly enough to offset attackers’ faster exploit-development workflows; this single reported case does not establish that balance yet.
The trend: AI is moving from a general-purpose aid for cyber research into an operational factor in the race between vulnerability discovery, exploitation, and defense.