Skip to content
    AI Threats

    Hackers Used AI to Build a Zero-Day Exploit. Google Caught It First.

    Researchers found ‘hallucinated’ artefacts in the exploit code — including a fake CVSS score the model had invented.

    Part of: AI Reckoning

    By The Daily Stash Editors · Editorial teamLast verified May 8, 20267 min read
    Hackers Used AI to Build a Zero-Day Exploit. Google Caught It First. — AI Threats feature on The Daily Stash

    For two years, security researchers have been warning that AI would eventually find its first real zero-day in the wild. In May 2026, Google’s Threat Intelligence Group said it watched that happen — and stopped it before the criminal group behind it could weaponise it at scale.

    The vulnerability — Google has not publicly named it — was a previously unknown flaw in widely deployed enterprise software. The exploit code was obtained during routine threat-intel monitoring of a known cybercrime group.

    What gave it away: parts of the exploit referenced a CVSS severity score that didn’t exist in any database. The number was internally consistent and plausible-sounding, which is exactly how large-language-model hallucinations usually present.

    Defensively, this is the news the security community has been preparing for since 2023. Offensive AI tooling reduces the cost of vulnerability discovery from ‘elite researcher with months of focus’ to ‘mid-skill operator with API credits.’ The economics of zero-day production change.

    Related read: The themed Canadian casino site players keep telling their friends about. Sponsored

    Google’s framing is deliberately careful: this is the first time they have ‘high-confidence’ attribution of an AI-generated zero-day in the wild. It is almost certainly not the first time it has happened — only the first time it’s been caught.

    The countermove is also AI-led. Vendors are now running their own AI-driven fuzzers against their own codebases on a continuous basis. The arms race is no longer about humans vs. humans with AI assistance. It is about whose AI finds the bug first.

    Elsewhere on The Daily Stash

    Sources

    1. The Verge — Google Stopped a Zero-Day Hack That It Says Was Developed With AI
    2. CyberScoop — Google Spotted an AI-Developed Zero-Day Before Attackers Could Use It
    3. Reuters technology coverage
    4. BBC Technology
    5. The Guardian technology

    Original editorial. Written by The Daily Stash Editors. See our editorial policy.