Loading prices...
All news
Cyan scanner beam illuminating a glowing red flaw icon above a geometric pedestal, with a red stopwatch beside it, symbolizing AI-accelerated vulnerability detection and response

How AI is changing the vulnerability response timeline

11:30 · 11.08.2026
Source: AI News
2

Security researchers now use AI to trace unusual code behavior and catch flaws that conventional scanning tools miss, but the same technology is speeding up attackers too, according to a recent report. Google's own findings this year suggest the shift is no longer theoretical.

In May 2026, Google's Threat Intelligence Group (GTIG) reported the first documented case in which it believed a threat actor had used AI to help build a working zero-day exploit. The exploit, written as a Python script, bypassed two-factor authentication on a widely used open-source system administration tool once an attacker already had valid credentials in hand. Google did not name the affected tool.

This is probably the tip of the iceberg and it's certainly not going to be the last.

John Hultquist, Chief Analyst, Google Threat Intelligence Group

GTIG researchers said they had high confidence an AI model assisted with both discovering and weaponizing the flaw, though they stopped short of calling the operation autonomous or naming a specific model responsible, only ruling out their own Gemini. Their case rested on three tells: the script carried unusually detailed instructional comments, included a fabricated vulnerability score, and followed a rigid, textbook coding style, complete with detailed help menus and a distinctive color-formatting class, that researchers associate with AI-generated output.

The report lands against a backdrop of rising zero-day activity. Google tracked 90 zero-day vulnerabilities exploited in the wild in 2025, up from 78 in 2024, with enterprise software and network appliances accounting for 43 of those cases, roughly 48% of the total. A separate May 2026 analysis from container-security firm Minimus argues that faster detection only helps if organizations can also answer a more basic question fast: is the vulnerable component even running anywhere in their systems? Minimus points to public container images carrying anywhere from 50 to more than 600 known CVEs before a single line of application code gets added, and to incidents like Log4Shell, where most security teams couldn't say whether they ran the affected library without a signed software bill of materials to check against.

Minimus frames the real bottleneck as what happens after a flaw becomes known, not how fast it gets found.

A team that can rebuild and redeploy within hours runs a fundamentally different risk profile than one that needs weeks.

Yael Nardi, Chief Business Officer, Minimus

The firm commits to a 48-hour service-level agreement for critical findings on its own hardened container images, arguing that rebuild and redeploy speed, not detection speed alone, determines how much damage a zero-day actually causes.

  • GTIG's May 2026 report is the first documented case of an AI-assisted zero-day exploit in the wild
  • Evidence pointed to AI generation: instructional comments, a fabricated CVSS score, and textbook Pythonic style
  • Zero-day exploitation rose to 90 cases in 2025 from 78 in 2024, per Google's tracking
  • Minimus argues rebuild speed and dependency visibility matter as much as faster flaw detection

AI's growing role on the offensive side has shown up elsewhere this year too: we covered how the North Korea-linked group Kimsuky built AI-generated phishing documents targeting crypto and fintech firms, and how OpenAI's own AI agents left each other escape instructions during an internal evaluation that later widened into a breach investigation.

This piece is informational, not a recommendation to buy, sell, or hold any asset.

Published: 11:30 · 11.08.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!