WEATHER ALERT

Google disrupts hackers using AI to exploit an unknown weakness in a company’s digital defense

Advertisement

Advertise with us

Google said Monday that it had disrupted a criminal group's attempt to use artificial intelligence to exploit another company's previously unknown digital vulnerability, adding to heightened worries across government and private industry about AI's risks for cybersecurity.

Read this article for free:

or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Google said Monday that it had disrupted a criminal group’s attempt to use artificial intelligence to exploit another company’s previously unknown digital vulnerability, adding to heightened worries across government and private industry about AI’s risks for cybersecurity.

Google shared limited information about the attackers and the target, but John Hultquist, chief analyst at the tech giant’s threat intelligence arm, said it represents a moment cybersecurity experts have warned about for years: malicious hackers arming themselves with AI to supercharge their ability to break into the world’s computers.

“It’s here,” Hultquist said. “The era of AI-driven vulnerability and exploitation is already here.”

FILE - A woman walks by a giant screen displaying the Google logo at an event at the Paris Google Lab on the sidelines of the AI Action Summit in Paris, Feb. 9, 2025. (AP Photo/Thibault Camus, File)
FILE - A woman walks by a giant screen displaying the Google logo at an event at the Paris Google Lab on the sidelines of the AI Action Summit in Paris, Feb. 9, 2025. (AP Photo/Thibault Camus, File)

It comes at a time of leaps in AI’s abilities to find vulnerabilities, including the Mythos model announced a month ago by Anthropic. Among those trying to bolster their defenses is President Donald Trump’s White House, which has shifted its approach in how it plans to vet the most powerful AI models before their public release.

After following through with a campaign promise to repeal Democratic President Joe Biden’s guardrails around the fast-developing technology, the Republican administration and its allies are now sending mixed signals about the government playing a larger role in AI oversight.

“Some people don’t want there to be a regulatory response to this and others do,” said Dean Ball, a senior fellow at the Foundation for American Innovation who was previously a White House tech policy adviser and a lead author of Trump’s AI policy roadmap last year.

“I don’t like regulation,” Ball said. “I would prefer for things not to be regulated. But I think we need to in this case.”

Google says it found evidence of AI helping in cyberattack

Google said it observed a group of prominent “threat actors” planning a big operation relying on a bug they had found. The vulnerability allowed them to bypass two-factor authentication to access a popular online system administration tool, which Google declined to name.

The company called it a zero-day exploit, a cyberattack that takes advantage of a previously unknown security vulnerability. “Zero-day” refers to the fact that the security engineers have had zero days to develop a fix for the vulnerability.

Google said it notified the affected company and law enforcement and was able to disrupt the operation before it caused any damage. But as it traced the hackers’ footprints, it found evidence they had used an AI large language model — the same technology that powers popular chatbots — to discover the vulnerability.

Google didn’t reveal which AI model was used in the cyberattack, only that it was most likely not Google’s own Gemini or Anthropic’s Claude Mythos. Google also didn’t reveal which group it suspected in the attack but said there was no evidence it was tied to an adversarial government, though the company said groups tied to China and North Korea have been exploring similar techniques.

Hultquist said that compared with government spies who typically work slowly and quietly, criminal hackers have some of the most to gain from AI’s “tremendous capability for speed” in finding and weaponizing security bugs.

“There’s a race between you and them to stop them before they can essentially get whatever data they need to extort you with, or launch ransomware,” he said in an interview. “AI is going to be a huge advantage because they can move a lot faster.”

Anthropic’s Mythos has sparked a panic and call for regulation

Trump’s Commerce Department announced last week that it signed new agreements with Google, Microsoft and Elon Musk’s xAI to evaluate their most powerful AI models before their public release, building on previous agreements the Biden administration made with Anthropic and ChatGPT maker OpenAI. But the announcement later disappeared from the Commerce Department website.

It was the latest example of jumbled signals from the Trump administration in the month since Anthropic announced a new model it called Mythos that it said was so “strikingly capable” at hacking and cybersecurity work that it could only release it to a small group of trusted organizations.

Anthropic created an initiative called Project Glasswing bringing together tech giants including Amazon, Apple, Google and Microsoft, along with other companies like JPMorgan Chase, in hopes of securing the world’s critical software from “severe” fallout that the new model could pose to public safety, national security and the economy. But its relationship with the U.S. government was complicated by a public and legal fight with the Pentagon and Trump himself over military use of its AI technology.

Its top rival, OpenAI, has since introduced a similar model. The company said Friday it was releasing a specialized cybersecurity version of ChatGPT that would only be available to “defenders responsible for securing critical infrastructure” to help them find and patch vulnerabilities in their code.

Ball said he’s optimistic that, over the long term, AI tools that are increasingly good at coding will make us safer from the routine cyberattacks afflicting hospitals, schools and other organizations. In the meantime, however, he said there are “untold trillions of lines of software code” supporting the world’s computing systems that are at risk if AI tools are unleashed to exploit all of their bugs.

It could take years to harden all of that software — a process that Ball believes would be aided by coordination from the U.S. government.

In the meantime, Ball predicts a “transitional period” where cybersecurity risks rise significantly and “the world might actually be more dangerous.”

Report Error Submit a Tip

More Stories

Protests spur Ukraine military reshuffle

Kyle Volpi Hiebert 5 minute read Preview

Protests spur Ukraine military reshuffle

Kyle Volpi Hiebert 5 minute read 2:01 AM CDT

Even nations fighting for their survival can’t escape politics. “The president should not choose sides during a war,” Ukrainian President Volodymyr Zelenskyy told reporters earlier this month after sacking his defence minister.

Read
2:01 AM CDT

Anishinaabe Days teepee poles vandalized

Nicole Buffie 4 minute read Preview

Anishinaabe Days teepee poles vandalized

Nicole Buffie 4 minute read Updated: Yesterday at 8:16 PM CDT

An act of vandalism to a teepee at the Treaty One Development Corp’s Anishinaabe Days did not stop the celebrations from continuing over the weekend.

Someone deliberately cut the poles used to erect the site’s teepee before the event began, Treaty One executive director Jason Whitford said Sunday.

The family responsible for overseeing the teepee and its construction at the site, Naawi-Oodena  on Kenaston Boulevard, went to the site on Friday to erect the teepee when they noticed someone had taken a saw and cut all 15 of its poles in half.

“They were stored in a safe place, and they were stored properly as per protocol,” Whitford said. “They were in an area where there was no construction so they were isolated from any activity.”

Read
Updated: Yesterday at 8:16 PM CDT

A small step among troubling signs

Editorial 4 minute read Preview

A small step among troubling signs

Editorial 4 minute read Updated: 8:02 AM CDT

There’s no getting around the fact — to many people, downtown Winnipeg is unsafe. Period.

Read
Updated: 8:02 AM CDT

Dropping the gloves to make the point

Editorial 4 minute read Preview

Dropping the gloves to make the point

Editorial 4 minute read Saturday, Jul. 25, 2026

In hockey parlance, it’s called “shedding,” the moment in a game when you are forced to deal with an instigator by dropping (shedding) your gloves for an all-out brawl.

That term is a deep cut from hockey culture that Prime Minister Mark Carney — he of the “elbows up” phenomenon — may need to not only embrace but practise more often in the face of yet another round of overly punitive tariffs imposed by United States President Donald Trump.

To be fair, under Carney’s leadership, Canada has not exactly rolled over in the face of Trump’s bully-boy tactics.

Yes, Canada has made concessions to placate Trump to further a new continental trade agreement: investing more money to combat the cross-border flow of fentanyl that isn’t actually happening, stalling efforts to tax streaming companies as most European countries already do, and — most recently — giving Trump a cut of profits from the Canadian-made, Canadian-paid Gordie Howe bridge between Windsor and Detroit.

Read
Saturday, Jul. 25, 2026

Man, 20, faces charges in street-racing incident

1 minute read Updated: Yesterday at 11:37 PM CDT

Speeding drivers were racing through Elmwood at up to 200 km/h overnight, Winnipeg police say.

Around 2 a.m. July 26, police got reports of a Corvette and other vehicles racing along Disraeli Freeway. Using the Winnipeg Police Service's helicopter, officers monitored the vehicles and recorded speeds, including vehicles crossing the Nairn overpass at up to 200 km/hr.

Officers with the central traffic unit tried to pull over a Jeep and a Corvette at Lagimodiere Boulevard and Regent Avenue. The driver of the Corvette didn't stop and sped past police, eventually stopping in the 100 block of Johnson Avenue where the driver and passenger got out and ran.

The K9 unit tracked the suspects to the 100 block of Poplar Avenue. One of them was taken down by a police dog and received medical attention. Both were taken into custody.

City has plenty of frozen dessert oases to discover

AV Kitching 6 minute read Preview

City has plenty of frozen dessert oases to discover

AV Kitching 6 minute read Updated: 11:23 AM CDT

No matter the weather, ice cream is always a welcome addition to the day.

It’s a rite of passage as, at the slightest hint of a thaw, Winnipeggers descend in droves, heeding the siren call of institutions such as Sargent Sundae (2053 Portage Ave.) and Bridge Drive-In (766 Jubilee Ave. and 1680 Main St.) that slide open their shutters any time from late March to early April, ready to welcome dedicated connoisseurs seeking their first taste of the season.

We’re blessed with an abundance of ice cream joints in this city, ranging from brick-and-mortar storefronts to mobile carts and pop-up stalls, all serving generous scoops of childhood faves alongside rather more innovative flavours.

With so many dairy bars and frozen dessert parlours dotted around, there’s no need to choose just one spot to satisfy your sweet tooth.

Read
Updated: 11:23 AM CDT