logo

Google researchers uncover criminal zero-day exploit likely built with AI

ID: d0f28ae7-86a4-5400-95ee-0b69dbc8e5f3

STIX ID: report--d0f28ae7-86a4-5400-95ee-0b69dbc8e5f3

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Mirko Zorz

...
...

Google Threat Intelligence researchers link a zero-day web administration-tool exploit to AI-assisted development and detail multiple AI-influenced threats: LLM-assisted malware families (CANFAIL, LONGSTREAM) that use decoy code for obfuscation, the autonomous Android backdoor PROMPTSPY that leverages LLM APIs to perform UI actions and capture/replay biometric data, and a March 2026 supply-chain compromise of LiteLLM and Trivy that embedded a credential stealer (SANDCLOCK) to exfiltrate cloud and GitHub secrets later used in ransomware partnerships — illustrating growing risks to AI infrastructure and operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.