Google Detects First AI-Generated Zero-Day Exploit
2026-05-11T13:24:07Z•3614f5b483842b0c827c7ef3a48d518939089469bdcd972cb79c731e69c78687
2fa-bypassai-generated-exploitcisacopy-fail-2data-breachdirty-fraggithub-compromisejenkinslaw-enforcementlinux-vulnerabilitymarketplace-takedownotp-theftpamdoorapatchingpersonal-dataphishing-campaignsupply-chain-attackzero-day
What happened
Multiple high-impact security incidents reported: Google says it detected the first AI-generated zero-day exploit (designed to bypass 2FA) attributed to a prominent cybercrime group. A Skoda online shop vulnerability exposed customer PII (names, addresses, emails, phones). Supply-chain compromises reported — a malicious Checkmarx Jenkins AST plugin was published to the Jenkins Marketplace, and SailPoint disclosed a GitHub repository hack (no customer production data impacted). A widespread Linux vulnerability dubbed “Dirty Frag” (Copy Fail 2) was disclosed before a patch and is tracked as CVE-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 3614f5b483842b0c827c7ef3a48d518939089469bdcd972cb79c731e69c78687
- Enrichment time
- 2026-05-11T13:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.