logo

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation

ID: e4f5b02d-9199-555a-822f-f5a7c8b88c47

STIX ID: report--e4f5b02d-9199-555a-822f-f5a7c8b88c47

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

Google disclosed an active mass vulnerability exploitation campaign in which an unknown cybercrime actor used a zero-day Python-based exploit—showing hallmarks of LLM-generated code—to bypass two-factor authentication in a widely used open-source web administration tool; Google worked with the vendor to remediate the flaw. The report also details PromptSpy, an Android backdoor that abuses Gemini for autonomous interface navigation, biometric capture/replay, resilient C2 updates, and anti-uninstallation measures, and highlights multiple APT and criminal groups leveraging AI/LLMs, shadow API relay markets, and agentic tools to scale vulnerability discovery, exploit development, and supply-chain style attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.