Google Blocks First LLM-Generated Zero-Day Used in a Real-World Attack: A Historic Milestone

Google blocca il primo zero-day generato da un LLM: una svolta storica

In 2026, Google’s Threat Intelligence Group (GTIG) documented and neutralized the first zero-day vulnerability generated by a large language model (LLM) and weaponized in an actual cyberattack. This marks an unprecedented milestone in cybersecurity history: a criminal group had harnessed artificial intelligence to discover and exploit a critical vulnerability in the wild.

What Happened: The Facts of the Incident

The Vulnerability and the Target

The target was a widely used open-source web administration tool. The vulnerability allowed attackers to bypass two-factor authentication (2FA), though exploiting it still required possession of valid user credentials.

Google alerted the vendor before a mass exploitation campaign could be launched. The swift intervention prevented large-scale damage and stands as a textbook example of responsible disclosure done right.

The AI Fingerprints

The exploit code was written in Python and bore unmistakable hallmarks of LLM-generated output. Specifically, researchers identified:

  • Excessively didactic docstrings, highly unusual in real-world offensive code
  • Textbook-style formatting, characteristic of language models trained on academic corpora
  • A hallucinated CVSS score, a severity rating fabricated by the model with no factual basis

These telltale signs allowed researchers to attribute the code’s authorship to a generative AI system.

The Threat Actor: A Financially Motivated Criminal Group

Who Was Behind the Attack

Google has not publicly named the group responsible. However, it describes the organization as a high-profile criminal outfit with a well-documented history of mass exploitation campaigns.

One distinction is worth underscoring: the threat actor has no known ties to state-sponsored groups such as those operating on behalf of China (PRC) or North Korea (DPRK). This is a financially motivated criminal organization — and that fact reshapes the risk landscape entirely. Offensive AI is no longer the exclusive domain of nation-states.

A Rapidly Shifting Threat Environment

This incident does not stand alone. In November 2025, Anthropic had flagged Beijing-linked hackers fully automating attacks with AI assistance. As far back as late 2024, Google’s own Big Sleep project had demonstrated that an AI agent could autonomously discover zero-days — though that was a defensive application. 2026 marks the first confirmed case of adversarial weaponization of that same capability.

Meanwhile, North Korea’s APT45 had already deployed agentic tools such as Strix and Hexstrike against Japanese tech companies, while Russia-linked groups leveraged AI to target Ukrainian networks. Cybercriminals have simply followed the playbook pioneered by nation-states.

Defensive Implications for CISOs and Security Teams

Immediate Priorities

Organizations must act on multiple fronts simultaneously. Immediate priorities include:

  1. Strengthening 2FA implementation. Eliminate hardcoded exceptions in authentication logic and audit for dormant bugs that appear patched but still bypass controls.
  2. Monitoring open-source administration tools. Apply patches immediately upon release. These tools are now proven targets of mass exploitation campaigns.
  3. Deploying RASP and behavioral monitoring on authentication services to detect anomalous bypass attempts in real time.

Threat Hunting for AI-Generated Code

Perhaps the most significant new challenge for blue teams lies in hunting for AI-generated indicators. Security teams must now scan logs and network traffic for the fingerprints of machine-authored code — excessive docstrings, textbook formatting, fabricated metadata. These are the new indicators of compromise.

Over the longer term, organizations should consider adopting AI-driven vulnerability discovery tools internally, with the goal of achieving parity with attackers. Models like Anthropic’s Mythos, deployed within controlled sandbox environments, represent a concrete path forward.

Conclusion: The Era of Offensive AI Has Arrived

The first LLM-generated zero-day used in a real attack is not a theoretical warning — it is a documented fact. A line has been crossed.

Open-source web administration tools remain high-value targets: they centralize control over IT infrastructure and frequently operate with elevated privileges. When that attack surface is combined with offensive AI, exploitation becomes industrialized and systematic.

CISOs must update their risk models now. Artificial intelligence is not solely a defensive asset. It is already a weapon in the hands of adversaries.


Sources:


The emergence of AI-generated zero-days makes timely threat intelligence sharing an operational necessity, not an optional best practice. Platforms like IsacChain enable organizations to exchange indicators of compromise linked to AI-generated code in a secure and verifiable way, backed by a blockchain architecture that guarantees the integrity and traceability of shared data. The platform’s built-in automated NIS2 compliance features also allow security teams to continuously document incident response activities, significantly reducing their administrative burden. Discover how IsacChain can help your organization at www.isacchain.com