• Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Login
Join Free
Home
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Asia
Africa
Europe
Latin America
Middle East
North America
Coming Soon
Job Board
Events
Contact Awards
USMC Deception Manual
Login
Join Free
Home Global Operations

Google AI Agent Flags First Criminal AI-Built Zero-Day Before Mass Exploitation

  • SOFX Staff Writer
  • May 13, 2026
Illustrative image: A hooded figure at a laptop surrounded by streaming code, representing a cyberattack or hacking operation. (Credit: Songsak C / Shutterstock)
Share on FacebookShare on TwitterLinkedIn

Google’s Threat Intelligence Group on May 12 said it disrupted a planned mass exploitation campaign after identifying what it assesses with high confidence is the first zero-day exploit built by criminal hackers using artificial intelligence.

The criminal group built the exploit as a Python script targeting a two-factor authentication (2FA) bypass in a popular open-source, web-based system administration tool. Google Threat Intelligence Group (GTIG) coordinated with the affected vendor to patch the flaw before the campaign could be executed.

Google GTIG confirms the first AI-built zero-day exploit used in the wild. Discover how AI is industrializing cyber warfare and how Big Sleep is fighting back.#AICyberSecurity #ZeroDay #GoogleThreatIntel #InfoSec #CyberWarfare #BigSleepAI #Mandianthttps://t.co/ozBZSZZ0r5 pic.twitter.com/1bosroEuMg

— Gray Hats (@the_yellow_fall) May 12, 2026


“The criminal threat actor planned to use it in a mass exploitation event but our proactive counter discovery may have prevented its use,” GTIG stated in its report.

The flaw was a semantic logic error, a hardcoded trust assumption contradicting the application’s authentication enforcement. GTIG said frontier large language models (LLMs) excel at surfacing this class of flaw by reasoning through developer intent rather than analyzing crash signatures.

The script’s structure pointed to LLM generation, including a hallucinated Common Vulnerability Scoring System (CVSS) score, educational docstrings, and textbook Pythonic formatting. GTIG said it does not believe its Gemini model was used.

The report also detailed previously unreported capabilities in PROMPTSPY, an Android backdoor ESET first identified in February 2026 that abuses Google’s Gemini application programming interface (API) to operate autonomously on compromised devices.

GTIG found the backdoor’s “GeminiAutomationAgent” module serializes a device’s user interface into XML, sending it to the gemini-2.5-flash-lite model for gesture commands including CLICK and SWIPE.

PROMPTSPY can also capture biometric lock screen data and block uninstallation by rendering an invisible overlay over the device’s Uninstall button.

GTIG’s report confirmed that Big Sleep, an AI vulnerability-scanning agent developed with Google DeepMind, assisted in detecting the criminal group’s exploit before deployment. It marks the first documented instance of an AI-built exploit being interdicted by a separate AI system.

SOFX Staff Writer

SOFX Staff Writer

The Editor Staff at SOFX comprises a diverse, global team of dedicated staff writers and skilled freelancers. Together, they form the backbone of our reporting and content creation.

Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
ADVERTISEMENT

Trending News

SITREP MAY 2026: TAIWAN-CHINA COLLISION

SITREP MAY 2026: TAIWAN-CHINA COLLISION

by Dino Garner
June 3, 2026
0

Bottom Line Up Front The line that has held across the Taiwan Strait since the first of October 1949 held...

New Technology Turns Ordinary WiFi Into a System That Can Identify People With 99.5% Accuracy

New Technology Turns Ordinary WiFi Into a System That Can Identify People With 99.5% Accuracy

by SOFX Staff Writer
May 27, 2026
2

Researchers in Germany are warning that ordinary WiFi routers could be used as a form of invisible surveillance capable of...

FBI, DHS Track ‘Anti-Tech Extremism’ as AI Backlash Grows

FBI, DHS Track ‘Anti-Tech Extremism’ as AI Backlash Grows

by SOFX Staff Writer
June 3, 2026
5

Federal law enforcement agencies are tracking what they describe as an emerging threat of “anti-tech extremism” as concerns over artificial...

The SCAR-H’s 17-Year Run Soon Ends as SOCOM Adopts a Rifle That Shoots Two Calibers

The SCAR-H’s 17-Year Run Soon Ends as SOCOM Adopts a Rifle That Shoots Two Calibers

by SOFX Staff Writer
May 29, 2026
2

U.S. Special Operations Command expects to begin receiving the MK24 rifle from LMT Defense before the end of September, replacing...

ADVERTISEMENT
ADVERTISEMENT
Next Post
Fiber Optic Lines Can Record Nearby Speech and Evade Bug Detectors, Researchers Find

Fiber Optic Lines Can Record Nearby Speech and Evade Bug Detectors, Researchers Find

CBO Pegs Golden Dome at $1.2 Trillion as Pentagon Weighs Dropping Space Interceptors

CBO Pegs Golden Dome at $1.2 Trillion as Pentagon Weighs Dropping Space Interceptors

997 Morrison Dr. Suite 200, Charleston, SC 29403

News

  • Global Operations
  • Special Interest
  • Industry
  • Global Operations
  • Special Interest
  • Industry

Resources

  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
  • About Us
  • Contact Us
  • Advertise with Us
  • Editorial Policy
  • Privacy Policy
No Result
View All Result
  • Home
  • News
    • Global Operations
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
    • Industry
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
    • Special Interest
      • Asia
      • Africa
      • Europe
      • Latin America
      • Middle East
      • North America
      • Oceana
  • Market
    • Wired to Win
    • SOFX.NET
  • Intelligence
    • USMC Deception Manual
  • Resources
    • Contact Us
    • About Us
    • Editorial Policy
    • Privacy Policy
Subscribe
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.

Log in to your account

Lost your password?
wpDiscuz