Google’s finding is a major warning sign for defenders: AI is no longer just being used to write phishing emails or polish malware scripts, but may now be helping attackers discover and build working zero-day exploits. In this case, GTIG says a zero-day targeting an unnamed popular open-source web administration tool was likely generated with AI and could bypass 2FA, although the attack was stopped before mass exploitation.
This shifts the security challenge from “patch known CVEs quickly” to “assume exploit development cycles are getting shorter.” Web administration panels, remote management tools, and exposed open-source admin interfaces must be treated as high-risk assets: restrict access, enforce layered authentication, monitor unusual login flows, and avoid relying on 2FA alone as some magical security amulet. Attackers are using AI to move faster; defenders cannot keep responding at spreadsheet speed while pretending the dashboard is a strategy.
Researchers at Google Threat Intelligence Group (GTIG) say that a zero-day exploit targeting a popular open-source web administration tool was likely generated using AI. [...]
Source: Google: Hackers used AI to develop zero-day exploit for web admin tool via Bleeping Computer — published 11 May 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.