
What happened
Google Threat Intelligence Group's May 2026 report found that AI is now used in nearly all stages of cyberattacks. For the first time, it identified attackers using AI to develop exploits for zero-day vulnerabilities. One group found a zero-day that bypasses two-factor authentication in a widely used open-source web management tool, aiming to use it in large-scale attacks.
Why it matters
Open-weight models, which anyone can download and use without vendor control, make it easier to find vulnerabilities. Even without top-tier performance, these models can find 'considerable' vulnerabilities, says Daiyuki Fujii of Accenture Japan. This mainly boosts the efficiency of existing mass-targeting attacks rather than creating new advanced ones.
What to watch
The real test is whether open-weight models' lower barrier to use shifts attackers toward more sophisticated targets, or mainly boosts the efficiency of existing mass attacks. Watch how quickly the uncensored versions that weaken refusal training propagate.
Ask the AI about this article →
Summaries like this, in your inbox every morning.
The article highlights a shift: open-weight AI models remove the barriers that once limited who could develop sophisticated attacks. Unlike closed models, these can be downloaded and used without monitoring or control, allowing attackers to create uncensored versions. This does not necessarily create a wave of advanced attacks, but it lowers the cost of finding 'easy targets' to exploit, which is what most profit-driven attackers prefer.
Google's report marks a first: evidence of AI being used to develop zero-day exploits. The vulnerability found was a logic flaw, not a typical implementation error, suggesting that modern LLMs can uncover issues that traditional scanners miss. This is a new capability that could expand over time.
Fujii's advice for defenders is practical: assume attackers will get in and focus on limiting damage, as well as reducing the information available for AI-driven reconnaissance. He also stresses the importance of managing the backlog of unapplied patches, which is growing as vulnerabilities are found faster. Interestingly, he notes that defenders have an advantage because they know their own systems better than attackers, so using AI to find and fix vulnerabilities proactively can put them ahead.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
A developer tested whether ChatGPT would judge the same remote-work scenario differently when only the subject…

Google DeepMind ran 100 autonomous LLM agents using Gemini 3.1 Pro on 71 math problems

OpenAI, WAN-IFRA, and AIRPPU announced a joint initiative to help Ukrainian news organizations adopt AI

Palantir Technologies Inc

OpenAI has stated it is 'now moving into the AGI era,' and the company has also said it believes it knows how…

Artificial Analysis updated its Intelligence Index to v4.2 on September 4, adding two new tests: AA-Briefcase…
