First AI-developed ‘zero-day’ exploit discovered as AI threats become top concern
Summary
Google’s Threat Intelligence Group says it identified the first zero-day exploit believed to have been developed with AI, with high confidence that a threat actor used an LLM trained on historical vulnerability data to find and weaponize the flaw. Researchers also observed a shift to agentic AI that automates vulnerability discovery, reconnaissance, and tool orchestration, widening the attack surface and reducing human oversight. GTIG linked interest in AI-assisted exploits to threat actors from China and North Korea and worked with an impacted vendor to disrupt the campaign. Industry defenders, including Fortinet, say AI can also strengthen defenses and report rising concern among CISOs, with many organizations planning increased spending on AI-enabled security tools, workforce training, and a “human-on-the-loop” approach to oversight.