# Google flags AI‑crafted zero‑day hack by Chinese and North Korean

**Published:** 2026-05-11T13:00:07.000Z  
**Topic:** Google  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/69e267da-9a15-4099-892b-dd7e6c96cdc2

Google reports AI‑driven zero‑day exploit, AI bot attacks up 10× to 25 million incidents, and hackers leveraging Gemini and Anthropic tools – see the security

Google’s Threat Intelligence Group says it has uncovered the first known case of cyber‑criminals using artificial intelligence to build a zero‑day exploit, a vulnerability that software vendors did not know existed, and it blocked a planned mass‑exploitation campaign [2].

| At a glance | |
|---|---|
| AI‑crafted zero‑day | First evidence of AI‑generated exploit, targeting an unnamed open‑source IT admin tool |
| Bot attacks surge | AI‑driven attacks rose >10×, from 2 M to 25 M incidents worldwide in the past year |
| Anthropic’s Mythos | Limited‑release model dubbed “terrifying superhacker”, claimed to find flaws in every major OS and browser |
| Gemini misuse | Chinese‑linked group UNC2814 prompted Google’s Gemini chatbot to scan TP‑Link routers for vulnerabilities |

## AI as a hacking co‑pilot  

Google’s report describes how the exploit’s code showed “highly characteristic” AI patterns—textbook Python usage, detailed help menus, and even an AI hallucination referencing a non‑existent vulnerability—indicating the malicious program was generated with an AI tool, though the specific model was not identified [2]. The exploit was aimed at an open‑source, web‑based IT administration platform; Google’s early warning to the vendor is believed to have prevented a large‑scale attack. Researchers also noted that threat actors are now seeking “premium‑tier” access to AI models through anonymized pipelines, allowing them to bypass usage limits and scale misuse [1].

## State‑level actors and commercial AI tools  

The same Google briefing linked the activity to groups tied to Chinese and North Korean intelligence, confirming a “significant interest” from these nations in weaponising AI for vulnerability discovery [1][2]. In one documented case, a Chinese‑linked group (UNC2814) coaxed Google’s Gemini chatbot into acting as a network security expert and then asked it to locate weaknesses in TP‑Link routers, which are already banned in the U.S. for security concerns [2]. Meanwhile, Anthropic’s newly released Mythos model—available only to a handful of tech and financial firms—has been described by its creator as capable of uncovering software flaws across all major operating systems and browsers, effectively acting as a “superhacker” [1].

## The broader escalation  

The surge in AI‑enabled attacks is reflected in a ten‑fold increase in bot‑driven incidents, climbing from 2 million to 25 million over the last year, a trend that coincides with the rollout of advanced AI coding assistants from firms like Anthropic and OpenAI [1]. While these tools can accelerate defensive research, the same capabilities are being repurposed by low‑skill actors to execute sophisticated exploits that previously required years of expertise, according to threat analysts cited by Google and external experts [2].

## What to watch  
- **AI model access policies** – monitor how AI providers tighten or loosen premium‑tier access controls after these disclosures.  
- **Vendor patches** – watch for security updates to the targeted open‑source admin tool and related software that may be retrofitted with mitigations.  
- **State‑actor activity** – track further reports of Chinese or North Korean groups leveraging commercial AI services for cyber‑operations.

The emergence of AI‑generated zero‑day exploits signals a shift where the barrier to creating potent malware drops dramatically, raising questions about how quickly defensive AI can keep pace with increasingly automated offensive capabilities.

## Sources
1. AOL — [Hackers use AI to create worst security flaw for first time, Google reveals](https://www.aol.com/articles/hackers-ai-create-worst-security-135944000.html)
2. Forbes — [Cybercriminals Are Making Powerful Hacking Tools With AI, Google Warns](https://www.forbes.com/sites/thomasbrewster/2026/05/11/cybercriminals-make-powerful-zero-day-hack-with-ai-google-warns/)

---
Cite as: TrendWatcher, "Google flags AI‑crafted zero‑day hack by Chinese and North Korean", https://www.trendwatcher.in/article/69e267da-9a15-4099-892b-dd7e6c96cdc2
