Google Detects First AI-Generated Zero-Day Exploit

2026-05-11T13:24:07Z3614f5b483842b0c827c7ef3a48d518939089469bdcd972cb79c731e69c78687
2fa-bypassai-generated-exploitcisacopy-fail-2data-breachdirty-fraggithub-compromisejenkinslaw-enforcementlinux-vulnerabilitymarketplace-takedownotp-theftpamdoorapatchingpersonal-dataphishing-campaignsupply-chain-attackzero-day

What happened

Multiple high-impact security incidents reported: Google says it detected the first AI-generated zero-day exploit (designed to bypass 2FA) attributed to a prominent cybercrime group. A Skoda online shop vulnerability exposed customer PII (names, addresses, emails, phones). Supply-chain compromises reported — a malicious Checkmarx Jenkins AST plugin was published to the Jenkins Marketplace, and SailPoint disclosed a GitHub repository hack (no customer production data impacted). A widespread Linux vulnerability dubbed “Dirty Frag” (Copy Fail 2) was disclosed before a patch and is tracked as CVE-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
3614f5b483842b0c827c7ef3a48d518939089469bdcd972cb79c731e69c78687
Enrichment time
2026-05-11T13:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Google Detects First AI-Generated Zero-Day Exploit · Baitaphish