ClosedMedium impactAI Generated

Google GTIG: First AI-Generated Zero-Day Exploit Identified; State Actors Expand AI-Assisted Cyber Operations – May 2026

Occurred 11 May 2026·Detected 12 May 2026·
🇺🇸 Global – cyber operations attributed to actors linked to China, North Korea, and Russia; target software used worldwide2 reportsEnded 29 May 2026
CyberPropertyCyberCasualty & Liability

Google's Threat Intelligence Group (GTIG) has identified the first confirmed zero-day exploit believed to have been developed using AI, targeting an unnamed open-source web administration tool to bypass two-factor authentication. The Python exploit's structure — including hallucinated CVSS scores and LLM-characteristic formatting — provided high-confidence evidence of AI involvement. The attack was foiled before mass exploitation. GTIG also reported broader trends of Chinese (APT27, APT45) and North Korean (UNC2814, UNC5673, UNC6201) threat actors using AI for vulnerability discovery, while Russian actors employed AI-generated code to obfuscate malware and AI voice cloning in influence operations.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. The attack was foiled before mass exploitation, limiting immediate loss potential. However, the demonstrated capability for AI-assisted zero-day development represents a significant escalation in the cyber threat landscape, with potential to increase frequency and severity of future insured cyber events globally.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Geographic Zone Matches

4 active matches

  • OFAC Sanctioned Countries
    Rule-basedConfidence 100%
  • TRIA Certified Areas
    Rule-basedConfidence 100%
  • JWC Listed Areas
    Rule-basedConfidence 100%
  • EU Sanctions List
    Rule-basedConfidence 100%

Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.

Affected countries

🇨🇳 China🇬🇱 Global🇰🇵 North Korea🇷🇺 Russia🇺🇸 United States

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts