Google Threat Intelligence Group (GTIG) reports that a criminally used zero-day exploit was likely developed with AI-assisted help. GTIG says the exploit targets a widely used open-source, web-based system administration tool. According to the researchers, attackers who already had valid user credentials can use the flaw to bypass two-factor authentication, enabling access despite MFA protections.
Google attributes the vulnerability to a semantic logic error in the application: a hardcoded trust assumption by the developer conflicts with how the system enforces authentication. GTIG also states it worked with the affected software vendor as part of coordinated disclosure, though the specific vendor response and the exact release timeline are not detailed in the available summaries.
Both outlets describe the same core findings: the exploit is a real zero-day used by criminals, the targeted component is the same web administration tool, the bypass involves two-factor authentication, and the underlying cause is the same type of logic flaw. They also present the assessment that AI may have been involved in developing the exploit, based on GTIG’s analysis.