Google’s Threat Intelligence Group (GTIG) disclosed the first known case of a cybercriminal using an AI-developed zero-day exploit as part of a planned mass exploitation campaign. The flaw, a two-factor authentication bypass in an undisclosed open-source, web-based system administration tool, was implemented in a Python script bearing hallmarks of large-language-model-generated code, including a hallucinated CVSS score and unusually thorough educational docstrings. GTIG assessed with high confidence that an AI model had been used to discover and weaponize the vulnerability, and worked with the affected vendor to patch it and disrupt the threat actor’s campaign before it could be used at scale.