Google Detects First AI-Generated Zero-Day Exploit

https://www.securityweek.com/wp-content/uploads/2023/10/Zero-Day-Exploit.jpg

For the first time, Google has identified a zero-day exploit believed to have been developed using artificial intelligence.

The company published a new report on Monday summarizing its observations on the use of AI in the cyber threat landscape, drawing on data collected recently by Gemini, Google Threat Intelligence Group (GTIG), and Mandiant.

One of the most notable findings is that a prominent cybercrime group leveraged AI to develop a zero-day exploit designed to bypass two-factor authentication (2FA) on an open source web-based system administration tool. The exploit was implemented in a Python script.

The hacker group and the targeted tool have not been named, but Google said it worked with the impacted vendor to prevent mass exploitation, which appeared to be the threat actor’s plan.

“Although we do not believe Gemini was used, based on the structure and content of these exploits, we have high confidence that the actor...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more

https://tii.imgix.net/production/articles/17592/32572c7e-2961-40f3-b2dc-6fddc11c357a.jpg?fm=jpeg&auto=compress&w=610

Sources: Nvidia agrees to invest $2B in Lancium, the power infrastructure developer of the Stargate campus in Texas, plus $1B more if it hits certain thresholds

More: The Guardian, BBC, Wall Street Journal, Washington Post, First Judicial District Court of New Mexico, TechCrunch, The Verge, The Information, nmdoj.gov, Courthouse News Service, Fox News, CNBC, New York Times, Quartz, Fox Business, Amnesty International USA, Associated Press, Breitbart, Reuters, Raw Story, Engadget, Reclaim The Net, TheGrio, Deseret