top of page
AINews (3).png

Google Warns AI-Powered Cyberattacks Have Already Begun

  • Writer: Covertly AI
    Covertly AI
  • May 11
  • 3 min read

Artificial intelligence is rapidly changing cybersecurity, and Google’s latest findings show that AI-powered hacking is no longer just a future concern. Google’s Threat Intelligence Group says criminal groups and state-linked actors are already using commercial AI models to make cyberattacks faster, more advanced, and easier to scale. The findings have raised concerns among governments, technology companies, and cybersecurity experts about how powerful AI systems could be used to discover software weaknesses, create malicious code, and exploit digital defenses around the world.


Google said it recently disrupted a criminal group that was attempting to use AI to exploit a previously unknown security flaw in another company’s digital systems. The flaw was described as a zero-day vulnerability, which means software developers had no prior knowledge of it and had no time to create a fix before it could be targeted. Google said the weakness could have allowed hackers to bypass two-factor authentication protections on a popular online system administration tool. The company notified the affected firm and law enforcement, allowing the issue to be patched before the hackers caused damage.


The case is especially important because Google found evidence that an AI large language model helped the attackers discover or develop the vulnerability. Google did not identify the hackers, the target company, or the AI model used, but it said the model was most likely not Google’s Gemini or Anthropic’s Claude Mythos. The company also said there was no evidence the group was connected to a foreign government. However, Google’s report noted that state-linked groups from China, North Korea, and Russia have been experimenting with commercial AI tools, including Gemini, Claude, and OpenAI systems, to refine attacks, improve malware, target networks, and increase the scale of cyber operations.


Concerns about AI-driven hacking have grown since Anthropic limited the release of its powerful Mythos model. Anthropic said Mythos was capable of discovering zero-day vulnerabilities across major operating systems and web browsers, including flaws that had gone undetected for years. Because of these risks, the company restricted access to a small group of trusted organizations and launched Project Glasswing, an initiative involving companies such as Amazon, Apple, Google, Microsoft, and JPMorgan Chase to strengthen cybersecurity defenses. OpenAI has also introduced a specialized cybersecurity version of ChatGPT designed for defenders responsible for protecting critical infrastructure.


Cybersecurity experts warn that AI gives hackers a major advantage because of its speed. Criminal groups can use the technology to search for software weaknesses, test attack methods, and weaponize vulnerabilities much faster than before. This creates a race between attackers and defenders, where organizations must detect and patch flaws before hackers can use them for extortion, ransomware, or data theft. John Hultquist, chief analyst at Google Threat Intelligence Group, warned that the race to use AI in vulnerability discovery has already begun and that for every AI-linked zero-day found, many more may exist.


At the same time, some experts believe AI could improve cybersecurity in the long term. Defensive teams can use the same technology to scan code, identify bugs, and protect hospitals, schools, governments, companies, and public infrastructure from routine cyberattacks. However, the transition period may be risky because the world depends on trillions of lines of older software code that may contain hidden flaws. This has created growing debate over whether governments should play a stronger role in testing and monitoring advanced AI models before they are released.


The rise of AI-powered hacking shows how quickly artificial intelligence is reshaping digital security. What once seemed like a distant threat is now becoming a serious challenge for companies and governments around the world. AI may eventually help defenders build stronger and safer systems, but in the short term, it is also giving attackers new ways to move faster and strike harder. The future of cybersecurity will depend on whether organizations can use AI responsibly while preventing the same tools from becoming weapons in the hands of malicious actors.


Works Cited


Down, Aisha, and Dan Milmo. “AI-Powered Hacking Has Exploded into Industrial-Scale Threat, Google Says.” The Guardian, 11 May 2026, www.theguardian.com/technology/2026/may/11/ai-powered-hacking-industrial-scale-threat-three-months-google


O’Brien, Matt. “Google Disrupts Hackers Using AI to Exploit an Unknown Weakness in a Company’s Digital Defense.” CityNews Toronto, 11 May 2026, toronto.citynews.ca/2026/05/11/google-disrupts-hackers-using-ai-to-exploit-an-unknown-weakness-in-a-companys-digital-defense/


Miller, Maggie. “Google Says Hackers Used AI to Create Zero Day Security Flaw for the First Time.” Politico, 11 May 2026, www.politico.com/news/2026/05/11/google-hackers-ai-security-00913247


“Staying One Step Ahead of Hackers When It Comes to AI.” WIRED, www.wired.com/story/staying-one-step-ahead-of-hackers-when-it-comes-to-ai/


Comments


Subscribe to Our Newsletter

  • Instagram
  • Twitter
bottom of page