惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
有赞技术团队
有赞技术团队
P
Proofpoint News Feed
IT之家
IT之家
B
Blog
博客园_首页
量子位
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
J
Java Code Geeks
H
Help Net Security
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
D
DataBreaches.Net
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News

Futurism

Ordinary People Fear AI, While the Tech Leaders Working to Create a Permanent Underclass Say They’re Extremely Psyched About It Scientists and Lawmakers Horrified at Trump’s Brutal Budget for NASA Grimly Cyberpunk Video Shows Ukrainian Soldiers Leaning Out of Propeller Plane to Obliterate Drones With Rifles AI-Powered High School Scrapped After Protests Erupt Against It Eric Trump’s Crypto Company Is Falling Into Total Disaster Elon Musk Just Got Badly Humiliated in Court If You Bet on Polymarket, This New Study May Cause You Physical Pain If OpenAI Loses This Trial, It Could Effectively Be Eliminated in Its Current Form D4vd Bought Chainsaws and Body Bag on Amazon After Murder, Prosecutors Say, in the Most Grisly Case of Internet Brain Rot We’ve Ever Heard How to Get Rid of Reddit’s Giant App-Shilling Popup That Breaks Its Entire Mobile Site Mark Zuckerberg Just Got Shot Down by China, Again Reddit Intentionally Breaks Its Mobile Website, Demanding Users Download Its App Instead AI Spy Cameras Suddenly Blanketing America Man Trapped in Dystopian Nightmare Thanks to AI Surveillance Cameras Flagging His Every Move Sam Altman Caught in What May Be His Most Spectacular Lie Yet Woman Convicted for Attacking Police With Swarm of Furious Bees If You Thought Mark Zuckerberg Was a Pathetic Little Worm Before, Wait Until You Hear About His Latest Move A Tiny Town Is Building So Many Data Centers That There’ll Be Almost Nothing Else Left The War in Iran Is Causing China to Sell So Many Solar Panels That Your Jaw Will Drop Bitcoin Developers Are Debating a Move That Could Send Crypto Markets Into a Tailspin Waymo Has a Bike Lane Problem Tinder Scanning Users’ Eyeballs to Prove They Aren’t Creeps Two Delivery Bots Blunder Into the Middle of a Police Incident, Have Awkward Standoff Ransomware Negotiator Pleads Guilty to Deploying Ransomware Himself NASA Planning to Set First-Ever Fire on the Surface of the Moon Your Former Employer Is Selling Your Slacks and Emails to Train AI Tesla Quietly Buys Mysterious $2 Billion Entity The Number of Drones Being Deployed to Surveil Anti-Trump Protestors Is Staggering The US Military Just Arrested One of Its Soldiers for Making Ghoulish Polymarket Bets, and It Shows How Deep the Moral Rot of Prediction Markets Really Goes Elon Musk Fans Increasingly Disgusted by His Toxic Outbursts
Google Alarmed by Formidable AI-Powered Zero-Day Cyberattack
Frank Landym · 2026-05-12 · via Futurism

Google logo sign mounted on a teal-colored building facade with a bright yellow background. The letters are in the classic Google colors: blue, red, yellow, blue, and red.

Illustration by Tag Hartman-Simkins / Futurism. Source: Getty Images

Sign up to see the future, today

Can’t-miss innovations from the bleeding edge of science and tech

Google was rattled by a cyberattack that used AI to unearth a major flaw in its software that its own developers had no idea about.

The attack, which the New York Times reports was ultimately thwarted, was revealed by researchers at the tech giant on Monday. Their report didn’t specify who the actors behind it might be or when it occurred, but it was clear about what cutting-edge technology was at the heart of it.

“We have high confidence that the actor likely leveraged an AI model to support the discovery and weaponization of this vulnerability,” reads the report.

Google said the hackers used AI to identify what’s known as a zero-day vulnerability, a flaw in a piece of software that wasn’t previously known to its developers. When exploited, they leave the developers on the back foot, as the hackers are free to wreak havoc until the white hats figure out how to plug the hole. 

In this case, the zero-day bug would’ve allowed the hackers to bypass two-factor authentication on an unspecified “popular open-source, web-based system administration tool,” but only if the attackers knew a person’s user name and password. Given that two-factor authentication is the last meaningful line of defense for most users, and that their passwords are likely weak if they weren’t already leaked online in the first place, the ability to sidestep it could’ve been catastrophic even if the hackers weren’t armed with that information.

“The criminal threat actor planned to use it in a mass exploitation event but our proactive counter discovery may have prevented its use,” the report stated.

The researchers said this was the first example of a zero-day vulnerability being exploited by hackers that was developed with AI.

“It’s a taste of what’s to come,” John Hultquist, the chief analyst at Google Threat Intelligence Group, which published the report, told the NYT. “We believe this is the tip of the iceberg. This problem is probably much bigger; this is just the first tangible evidence that we can see.”

The attack will add to the atmosphere of unease around AI’s implications for cybersecurity, particularly with the release of Anthropic’s Claude Mythos model last month. Anthropic claimed that the AI system could find zero-day vulnerabilities “in every major operating system and every major web browser when directed by a user to do so,” a capability so potentially devastating that the company made a show of only sharing the model with a select group of companies and government agencies. Its rollout has drawn alarm from government leaders and security experts alike.

AI’s cybersecurity threat derives from its much-touted and ever-improving ability to write and parse code, which is being rapidly embraced by businesses across the tech and financial sectors. Like AI prose, AI code bears its own hallmarks, albeit more subtle. The Google researchers found that hacker’s malware contained an abundance of annotations that explain its code called docstrings, some hallucinated text, and “a structured, textbook Pythonic format highly characteristic of LLMs training data.”

More on AI: Vibe Coded Apps Are Spilling Users’ Personal Information Directly Into the Maw of Greedy Hackers