Google GTIG Confirms First AI-Built Zero-Day Exploit in the Wild: LLM-Generated 2FA Bypass on Open-Source Admin Tool
The Hacker News·high signal
Google's Threat Intelligence Group identified a threat actor using an AI model to discover and weaponize a zero-day vulnerability — a semantic logic flaw with hard-coded trust assumption that bypasses 2FA on a popular web admin tool. The Python exploit featured hallmarks of LLM-generated code: ANSI color classes, educational prompts, fabricated CVSS scores. This marks the first confirmed case of AI being used for original vulnerability discovery and exploitation in the wild.