Google thwarts hacker groups AI-driven mass exploitation plan
Google says it likely stopped a criminal hacking group from using artificial intelligence to orchestrate a mass exploitation attack, one that specifically targeted the bypass of two-factor authentication through a zero-day vulnerability. The intervention, disclosed by Googles Threat Intelligence Group, offers a concrete look at how AI is reshaping the cat-and-mouse game between attackers and defenders in cybersecurity. What happened and why it matters Google‘s Threat Intelligence Group identified a hacking operation that leveraged AI tools to research and plan the exploitation of a zero-day flaw. The attackers were using AI to find a previously unknown software vulnerability, then automating the process of weaponizing it at scale, specifically to defeat 2FA protections. Google’s defenses caught and neutralized the attempt before it could be deployed broadly. Googles analysts linked the broader trend of AI-assisted hacking to state-sponsored actors, particularly groups associated with Iran, China, North Korea, and Russia. These advanced persistent threat (APT) groups have been increasingly integrating AI into their operations, using it for reconnaissance, vulnerability research, and automating tasks that previously required significant human effort. Googles analysts noted that APT and information operations actors are using AI to accelerate routine hacking tasks rather than inventing entirely new categories of attack. The threats themselves