Google Halts First AI-Built Zero-Day As Daybreak Rivals Glasswing

Markets 2026-05-12 22:02

Google Halts First AI-Built Zero-Day As Daybreak Rivals Glasswing

Google says it disrupted a criminal hacking group's bid to weaponize a zero-day flaw built with help from an AI model, the first such case on record.

Google Stops AI-Crafted 2FA Bypass

The Google Threat Intelligence Group, known as GTIG, disclosed the intervention Monday in its latest AI Threat Tracker report.

Researchers found the flaw inside a Python script designed to bypass two-factor authentication on a popular open-source, web-based system administration tool.

Google declined to name the affected vendor or the threat actor.

GTIG said it worked with the vendor to patch the flaw and notified law enforcement before any mass exploitation could begin.

The team flagged telltale traces of machine authorship in the code, including a hallucinated CVSS severity score, educational docstrings, and a textbook Pythonic format consistent with large language model training data. Google added that it has high confidence an AI model assisted the discovery and weaponization, though it does not believe its own Gemini was involved.

Also Read: Tom Lee Calls Crypto Spring As Bitmine Stakes $11.1B In ETH

Experts Warn AI Hacking Era Is Here

John Hultquist, chief analyst at GTIG, called the case tangible evidence of a long-warned threat.

"It's here," Hultquist told reporters. The era of AI-driven vulnerability exploitation has already begun, he added, with visible cases pointing to many more out in the wild.

Security analysts say the flaw type matters as much as the tool used to find it.

The bug was a semantic logic error, a hardcoded trust assumption that traditional fuzzers and static scanners are poorly equipped to catch, but that frontier models can reason through.

Google also documented state-linked groups expanding AI use across the attack chain. North Korea's APT45 has been sending thousands of repetitive prompts to recursively analyze vulnerabilities, while a China-linked actor used a persona-driven jailbreak to push Gemini into researching firmware flaws.

Daybreak And Glasswing Lead Defender Push

The same week Google's findings went public, OpenAI launched Daybreak, a cybersecurity initiative pairing GPT-5.5 and Codex Security to help defenders find and patch flaws.

Daybreak runs on a tiered access system. Verified defenders can use GPT-5.5 with Trusted Access for Cyber, while a more permissive GPT-5.5-Cyber variant covers red teaming and controlled validation.

Sam Altman said OpenAI wants to work with as many companies as possible to continuously secure their software.

Daybreak enters a market already shaped by Anthropic's Project Glasswing, which uses Claude Mythos Preview to scan partner codebases for severe flaws. Apple, Microsoft, Google, Amazon, and JPMorgan Chase have signed on. The competing programs reflect a broader bet that frontier models can tip the balance toward defenders, even as attackers race to do the same.

Read Next: Sui Rallies 37% As Nasdaq Firm Locks Up 2.7% Of Supply

Share to:

This content is for informational purposes only and does not constitute investment advice.

Curated Series

SuperEx Popular Science Articles Column

SuperEx Popular Science Articles Column

This collection features informative articles about SuperEx, aiming to simplify complex cryptocurrency concepts for a wider audience. It covers the basics of trading, blockchain technology, and the features of the SuperEx platform. Through easy-to-understand content, it helps users navigate the world of digital assets with confidence and clarity.

Unstaked related news and market dynamics research

Unstaked related news and market dynamics research

Unstaked (UNSD) is a blockchain platform integrating AI agents for automated community engagement and social media interactions. Its native token supports governance, staking, and ecosystem features. This special feature explores Unstaked’s market updates, token dynamics, and platform development.

XRP News and Research

XRP News and Research

This series focuses on XRP, covering the latest news, market dynamics, and in-depth research. Featured analysis includes price trends, regulatory developments, and ecosystem growth, providing a clear overview of XRP's position and potential in the cryptocurrency market.

How do beginners trade options?How does option trading work?

How do beginners trade options?How does option trading work?

This special feature introduces the fundamentals of options trading for beginners, explaining how options work, their main types, and the mechanics behind trading them. It also explores key strategies, potential risks, and practical tips, helping readers build a clear foundation to approach the options market with confidence.

What are the risks of investing in cryptocurrency?

What are the risks of investing in cryptocurrency?

This special feature covers the risks of investing in cryptocurrency, explaining common challenges such as market volatility, security vulnerabilities, regulatory uncertainties, and potential scams. It also provides analysis of risk management strategies and mitigation techniques, helping readers gain a clear understanding of how to navigate the crypto market safely.