Google Thwarts AI‑Powered Attack, Uncovers Zero‑Day 2FA Bypass
Patch Google services to the latest security patch that mitigates the AI‑generated zero‑day exploit.
Patch Google services to the latest security patch that mitigates the AI‑generated zero‑day exploit immediately.
Summary
On 11 May 2026 a hacker collective launched a coordinated, AI‑driven assault on Google’s cloud and web services, targeting a range of products from Gmail to Google Cloud. The attackers employed machine‑learning models to scan for known CVEs, automatically generate exploit payloads, and attempt mass exploitation. Google’s security teams detected the intrusion early, blocked malicious traffic, and applied patches before any widespread damage could occur. The incident highlighted the growing threat of AI‑assisted attacks and the necessity of continuous, AI‑enhanced monitoring.
Earlier in the month, Google Threat Intelligence Group (GTIG) identified a zero‑day vulnerability that bypasses two‑factor authentication in an unnamed open‑source web administration tool. The exploit code, discovered before it could be mass‑exploited, contained educational docstrings, a hallucinated CVSS score, and a textbook Pythonic structure typical of large‑language‑model (LLM) training data. These clues indicated that the flaw was likely uncovered and coded by an AI system, exploiting a high‑level semantic logic bug rather than a traditional memory corruption or input‑sanitisation issue. Google ruled out Gemini as the LLM used and notified the tool’s developer, preventing potential exploitation.
The broader context of the attack underscores a trend among state‑aligned actors. Chinese and North Korean groups are increasingly using AI for vulnerability discovery and exploit development, while a Russian operation named “Overload” employed AI voice‑cloning to impersonate journalists in fabricated videos. Google also noted that the PromptSpy backdoor for Android integrates Gemini APIs for autonomous device interaction, capable of replaying authentication on the device. These developments illustrate how threat actors industrialise access to premium AI models through automated account creation, proxy relays, and account‑pooling infrastructure.
In response, Google tightened API‑key controls, enhanced its AI‑based threat‑detection pipeline, and reinforced real‑time monitoring of anomalous activity. The incident serves as a reminder that even large, well‑protected platforms can be targeted by sophisticated, automated threat actors, and it stresses the importance of timely patching and continuous threat intelligence for all enterprises.
Key changes
- Zero‑day exploit discovered by Google using AI for vulnerability discovery.
- AI system automated the search and creation of the exploit.
- First known malicious use of AI for exploit generation.
- Exploit remains unnamed and lacks a CVE identifier.
- Threat actor active for several weeks before detection.
- AI accelerated vulnerability discovery, reducing time to exploit.