Google says it has blocked an AI-developed zero-day exploit for the first time, a milestone that is both technically important and not especially comforting. According to the Google Threat Intelligence Group, prominent cyber crime threat actors were preparing to use the flaw in what the company described as a planned “mass exploitation event.”
The vulnerability targeted an unnamed open-source, web-based system administration tool. If used successfully, it would have allowed attackers to bypass two-factor authentication, which is generally supposed to be the point at which a system stops being casually breakable.
What Google says it found
Google’s researchers said the exploit was written in Python and included details that suggested artificial intelligence had helped create it. Those clues included a “hallucinated CVSS score” and formatting that appeared “structured” and “textbook” in a way consistent with large language model training data.
The flaw itself was not described as a simple coding typo. Google said it involved “a high-level semantic logic flaw where the developer hardcoded a trust assumption” inside the platform’s two-factor authentication system. In plainer terms: the system trusted something it should not have trusted, and attackers found a way to make that matter.
Google said it was able to “disrupt” the exploit before the planned large-scale attack unfolded. The company did not name the affected administration tool.



