
Google Threat Intelligence Group detected 'prominent cyber crime threat actors' planning to use a zero-day vulnerability in an unnamed open-source web-based system administration tool to bypass two-factor authentication in a 'mass exploitation event.' Google's researchers found evidence of AI involvement in the Python script, including a 'hallucinated CVSS score' and 'structured, textbook' formatting consistent with LLM training data.
The vulnerability exploited 'a high-level semantic logic flaw where the developer hardcoded a trust assumption' in the platform's 2FA system. Google was able to 'disrupt' this particular exploit, though the report notes researchers 'do not believe Gemini was used' in the attack.
Google's report indicates hackers are increasingly using AI to find and exploit security vulnerabilities, including through 'persona-driven jailbreaking' (instructing AI to roleplay as a security expert) and feeding AI models entire vulnerability repositories to refine AI-generated payloads before deployment.
Ask the AI about this article →
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
Visko raised $10 million in pre-seed funding from Llama Ventures and opened public access to its first foundat…
AI company Runway has unveiled Solaris, the first model in a new category it calls "Interface World Models." I…

Google's AI search gave advice to call emergency services for users alone with an African, Indian, or Pakistan…

John Deere introduced JD, a conversational AI tool that lets farmers ask open-ended questions about their hist…

Nvidia CEO Jensen Huang said on Fox Business that AI is creating 'hundreds of thousands' of jobs, including in…

Israeli startup DataAgent Ltd