Google stopped a zero-day hack that it says was developed with AI


For the first time, Google says it has spotted and stopped a zero-day exploit developed with AI. According to a report from Google Threat Intelligence Group (GTIG), “prominent cyber crime threat actors” were planning to use the vulnerability for a “mass exploitation event” that would have allowed them to bypass two-factor authentication on an unnamed “open-source, web-based system administration tool.”

Google’s researchers found hints in the Python script used for the exploit that indicated help from AI, like a “hallucinated CVSS score” and “structured, textbook” formatting consistent with LLM training data. The exploit takes advantage of “a high-level semantic logic flaw where the developer hardcoded a trust assumption” in the platform’s 2FA system. This follows weeks of handwringing over the capabilities of cybersecurity-focused AI models like Anthropic’s Mythos, and a recently disclosed Linux vulnerability that was discovered with AI assistance.

It’s the first time Google has found evidence that AI was involved in an attack like this, although Google’s researchers note that they “do not believe Gemini was used.” Google says it was able to “disrupt” this particular exploit, but also says hackers are increasingly using AI to find and take advantage of security vulnerabilities. The report also mentions AI as a target for attackers, saying “GTIG has observed adversaries increasingly target the integrated components that grant AI systems their utility, such as autonomous skills and third-party data connectors.”

Google’s report also details how hackers are using “persona-driven jailbreaking” to get AI to find security vulnerabilities for them, like an example prompt that instructs the AI to pretend it’s a security expert. Hackers are also feeding AI models whole repositories of vulnerability data, and using OpenClaw in ways that suggest “an interest in refining AI-generated payloads within controlled settings to increase exploit reliability prior to deployment.”



Source link

  • Related Posts

    There’s an Unhinged New Video Game About Trump and the Iran War

    A new video game about President Donald Trump’s war in Iran features fights with the pope and New York City mayor Zohran Mamdani. It’s impossible to win, and that’s the…

    Daniel Ek-backed defense tech Helsing to raise $1.2B at $18B valuation

    Five-year-old European military drone startup Helsing is reportedly close to raising a new $1.2 billion round at about an $18 billion valuation. The round is expected to be led by…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    UK alcohol deaths fall for first time since Covid pandemic

    UK alcohol deaths fall for first time since Covid pandemic

    Ontario Liberal interim leader says nomination was fair, despite candidate’s comments

    Ontario Liberal interim leader says nomination was fair, despite candidate’s comments

    CN Submits Comments to STB on Completeness of UP-NS Amended Merger Application

    Surprisingly, Canadians travelling to the U.S. rose in April for the first time since 2024

    County Championship: Muyeye hits century as Kent beat Gloucestershire

    County Championship: Muyeye hits century as Kent beat Gloucestershire

    Tell us your points and miles success and mistake stories!

    Tell us your points and miles success and mistake stories!