In May 2026, Google Threat Intelligence Group announced an unprecedented achievement: blocking the first zero-day exploit developed with the support of artificial intelligence. The attack was aimed at a web administration open-source tool, with the goal of bypassing two-factor authentication on a large scale.
Therefore, this episode marks a structural shift in the digital threat landscape. Cybercriminals are adopting language models to speed up the writing of malicious code. However, the same AI tools are already being used in defense. Google researchers identified the AI's fingerprint in the exploit by analyzing typical LLM anomalies: a hallucinated CVSS score and overly structured formatting.
In summary, Italian SMEs can no longer consider cybersecurity a topic reserved for large companies. We at SHM Studio we constantly monitor the evolution of digital risk to support client companies in building a secure and resilient online presence. Therefore, understanding this turning point is the first step to adopting adequate countermeasures.
What changed: AI enters the offensive arsenal
Until a few months ago, the use of artificial intelligence in cybersecurity was mainly associated with defense. However, a report published by The Verge May 2026 flipped this perspective. Google Threat Intelligence Group (GTIG) stated that they had identified and neutralized the first zero-day exploit developed with the support of a large language model.
The exploit targeted an open-source web administration tool, not yet publicly identified. The goal was to bypass two-factor authentication in a mass exploitation event. In other words, it was an attack designed to simultaneously hit a large number of vulnerable instances.
Therefore, this episode is not an isolated case to be quickly filed away. On the contrary, it represents a signal of discontinuity that deserves in-depth analysis, particularly for Italian SMEs managing exposed web infrastructures.
How researchers recognized the AI signature
The GTIG team identified the artificial intelligence footprint through the analysis of the Python script used for the exploit. In fact, two elements caught the analysts' attention.
- An hallucinated CVSS score: the vulnerability severity score had been incorrectly generated, with apparent but substantially invented accuracy. This behavior is typical of LLMs when operating on unverified technical data.
- Textbook formatting: the code structure and comments were excessively neat, consistent with the output patterns of language models trained on standardized technical documentation.
Therefore, AI did not write the exploit autonomously. It rather accelerated and structured the work of already competent criminal actors. This distinction is relevant: it lowers the entry barrier for those who want to conduct sophisticated attacks.
Furthermore, as highlighted by MIT Technology Review, the democratization of AI tools is reducing the technical gap between expert cybercriminals and less skilled actors.
The immediate impact on the digital threat landscape
This episode has direct implications on three levels. First of all, it changes the speed at which exploits are produced. A malicious actor can now delegate the code prototyping phase to AI, reducing development time.
Subsequently, it changes the risk profile for open-source technologies. Web administration tools, CMS, frameworks, and plugins are prime targets precisely because they are widely distributed. Consequently, a vulnerability exploited with AI can scale rapidly across thousands of installations.
Finally, it changes the necessary defensive model. Traditional solutions based on signatures and periodic updates are no longer sufficient. According to Gartner, global cybersecurity spending is constantly growing, but the speed of defense adaptation struggles to keep pace with that of attacks.
What to do now: the risk perimeter of Italian SMEs
Italian SMEs often operate with limited IT resources. However, this does not make them a secondary target. On the contrary, their lower response capacity makes them attractive targets for automated and scalable attacks.
In particular, companies using open-source tools for website, CRM, or e-commerce management should consider some priority actions.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.