Subscribe

The trick: Zero Underneath

At Black Hat, Google warned of AI-powered attackers.

Google's own tracker counts the breakthroughs: zero.

Issue 713 August 20265 receipts3 min

at a Black Hat media briefing, Google Threat Intelligence Group and Accenture said threat actors are using frontier and open-weight AI models to develop new exploits and new entry paths into corporate networks.

Before you read on. Your call?

Google's own written AI Threat Tracker says it 'has not yet observed' actors achieving breakthrough capabilities that alter the threat landscape. The headline 'new technique' is stealing tokens, cookies and session IDs, which infostealers did long before AI. The one confirmed AI-built zero-day was disclosed May 11 and closed before it was used.

0BREAKTHROUGH CAPABILITIES IN GTIG'S OWN TRACKER
1AI-BUILT ZERO-DAYS OBSERVED IN THE WILD
MAY 11WHEN GOOGLE LOGGED THAT ONE

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Zero Underneath: the headline number has nothing behind it. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“'Which of these entry paths did not exist before AI?' If the answer is stolen session cookies, that path is older than the models selling the panic.”

Receipts

  1. Supports cloud.google.com: For the first time, GTIG has identified a threat actor using a zero-day exploit that we believe was developed with AI
  2. Supports cloud.google.com: adversaries increasingly leverage these tools as expert-level force multipliers for vulnerability research and exploit development, including for zero-day vulnerabilities
  3. Refutes cloud.google.com: GTIG has not yet observed APT or information operations (IO) actors achieving breakthrough capabilities that fundamentally alter the threat landscape.
  4. Context infosecurity-magazine.com: An AI model was likely used to identify a zero-day vulnerability and weaponize it to exploit bypass two-factor authentication (2FA) protections on a popular open-source, web-based system administration tool.
  5. Context cnbc.com: Google's threat intelligence group said hackers are using AI models such as OpenClaw to uncover and exploit zero-day software vulnerabilities

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict,tell us. Corrections are loud here.