Google’s Threat Intelligence Group (GTIG) says it has identified what it describes as the first known case of a zero-day exploit being discovered and weaponized with assistance from an AI model. In its report, GTIG says it has “high confidence” that prominent cybercrime threat actors used AI to help find and develop a vulnerability in a widely used system administration tool. GTIG says the planned activity involved bypassing two-factor authentication (2FA) and that the threat actors were aiming for a “mass exploitation event.” Multiple outlets report that GTIG’s investigation links the effort to an unnamed actor and that Google’s proactive defenses stopped the attempted exploitation before it could be carried out. While the outlets agree on the general claims—AI assistance, a previously unknown (zero-day) vulnerability, 2FA bypass capability, and the disruption of an attempted large-scale campaign—most articles do not name the affected software or provide technical details of the vulnerability. The reporting frames the disclosure as a notable milestone in how AI may be used in real-world vulnerability research and exploit generation.