tech

Google stopped a zero-day hack that it says was developed with AI

Posts from this topic will be added to your daily email digest and your homepage feed.

Google stopped a zero-day hack that it says was developed with AI

TL;DR

  • Google's Threat Intelligence Group detected an AI-developed zero-day exploit intended for mass exploitation.
  • The exploit targeted a vulnerability in an unnamed open-source, web-based system administration tool, aiming to bypass two-factor authentication.
  • Hints of AI involvement included a "hallucinated CVSS score" and structured formatting consistent with LLM training data.
  • Hackers are increasingly using AI for finding security vulnerabilities, including through "persona-driven jailbreaking" and by feeding AI vulnerability data.
  • AI systems themselves are becoming targets, with adversaries attacking integrated components like autonomous skills and data connectors.
  • Google successfully disrupted this specific exploit but acknowledges the growing trend of AI-assisted cyberattacks.