tech
AI-assisted hacking is already here, Google warns
Researchers have found the first known case of cybercriminals using AI to exploit a zero-day flaw.

TL;DR
- Google has identified what appears to be the first known case of cybercriminals using AI to discover and weaponize a zero-day vulnerability.
- The exploit targeted a bug in a Python script, aiming to bypass two-factor authentication on an open-source system.
- AI-assisted code was used by threat actors to weaponize the vulnerability, identified by characteristics common in AI-generated code.
- Advanced AI models are becoming more adept at finding subtle security flaws that conventional tools miss.
- Both cybercriminals and nation-state hackers are increasingly interested in using AI to amplify attacks, with examples from North Korean and Chinese state actors.
- Google also discovered malware (PromptSpy) that uses Gemini to autonomously navigate Android devices.