, ,

Hackers Used AI to Create a Zero-Day Exploit — A Cybersecurity First

Recent Visitors: 502 For the first time on record, malicious hackers have used artificial intelligence to develop a zero-day security vulnerability — a landmark moment that security experts say signals a dangerous new era in cyber warfare. IDEA Television News Desk Google’s threat intelligence researchers have confirmed the milestone, revealing that threat actors leveraged AI…

IDEA Television News Desk

Google’s threat intelligence researchers have confirmed the milestone, revealing that threat actors leveraged AI tools to discover and weaponize an unknown software flaw before any patch existed. A zero-day vulnerability — so named because developers have “zero days” to fix it before it can be exploited — is among the most valuable weapons in a hacker’s arsenal.

The development marks a troubling turning point. Until now, AI’s role in cybersecurity had been primarily defensive, with tools like Google’s own “Big Sleep” AI agent being used to hunt down vulnerabilities before bad actors could find them. Google’s Big Sleep tool had previously made headlines for discovering a critical security flaw that was “only known to threat actors and was at risk of being exploited,” with the company claiming it was “the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild.” Now, that same technology paradigm appears to have been turned against defenders.

The news arrives against a backdrop of surging zero-day attacks. Google’s Threat Intelligence Group tracked 90 zero-day vulnerabilities actively exploited throughout 2025 — a 15% increase from 2024 — with nearly half targeting enterprise software and appliances. The exploitation of enterprise-grade technology reached an all-time high, with state-sponsored groups placing a strong emphasis on edge devices that often lack endpoint detection and response capabilities.

Experts had long warned this moment was coming. Google’s own analysts anticipated that “AI will accelerate the ongoing race between attackers and defenders in 2026, creating a more dynamic threat environment,” and that adversaries would use it to automate and scale attacks by accelerating reconnaissance, vulnerability discovery, and exploit development.

The broader picture painted by researchers is alarming. The average time to develop an exploit for a known vulnerability has collapsed from over 700 days in 2020 to just 44 days in 2025, and Mandiant’s M-Trends 2026 report found that time-to-exploit has effectively gone negative — with 28.3% of CVEs now being exploited within 24 hours of public disclosure.

For organisations, the message is urgent: the window between a vulnerability being discovered and it being weaponised is shrinking fast — and AI is now on both sides of the fight. Security teams are being urged to accelerate patch management, reduce attack surfaces, and deploy AI-assisted defences of their own before attackers get there first.

Leave a Reply

Your email address will not be published. Required fields are marked *