Google disrupts hackers using AI to exploit an unknown weakness in a company’s digital defense

Advertisement

Advertise with us

Google said Monday that it had disrupted a criminal group's attempt to use artificial intelligence to exploit another company's previously unknown digital vulnerability, adding to heightened worries across government and private industry about AI's risks for cybersecurity.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Google said Monday that it had disrupted a criminal group’s attempt to use artificial intelligence to exploit another company’s previously unknown digital vulnerability, adding to heightened worries across government and private industry about AI’s risks for cybersecurity.

Google shared limited information about the attackers and the target, but John Hultquist, chief analyst at the tech giant’s threat intelligence arm, said it represents a moment cybersecurity experts have warned about for years: malicious hackers arming themselves with AI to supercharge their ability to break into the world’s computers.

“It’s here,” Hultquist said. “The era of AI-driven vulnerability and exploitation is already here.”

FILE - A woman walks by a giant screen displaying the Google logo at an event at the Paris Google Lab on the sidelines of the AI Action Summit in Paris, Feb. 9, 2025. (AP Photo/Thibault Camus, File)
FILE - A woman walks by a giant screen displaying the Google logo at an event at the Paris Google Lab on the sidelines of the AI Action Summit in Paris, Feb. 9, 2025. (AP Photo/Thibault Camus, File)

It comes at a time of leaps in AI’s abilities to find vulnerabilities, including the Mythos model announced a month ago by Anthropic. Among those trying to bolster their defenses is President Donald Trump’s White House, which has shifted its approach in how it plans to vet the most powerful AI models before their public release.

After following through with a campaign promise to repeal Democratic President Joe Biden’s guardrails around the fast-developing technology, the Republican administration and its allies are now sending mixed signals about the government playing a larger role in AI oversight.

“Some people don’t want there to be a regulatory response to this and others do,” said Dean Ball, a senior fellow at the Foundation for American Innovation who was previously a White House tech policy adviser and a lead author of Trump’s AI policy roadmap last year.

“I don’t like regulation,” Ball said. “I would prefer for things not to be regulated. But I think we need to in this case.”

Google says it found evidence of AI helping in cyberattack

Google said it observed a group of prominent “threat actors” planning a big operation relying on a bug they had found. The vulnerability allowed them to bypass two-factor authentication to access a popular online system administration tool, which Google declined to name.

The company called it a zero-day exploit, a cyberattack that takes advantage of a previously unknown security vulnerability. “Zero-day” refers to the fact that the security engineers have had zero days to develop a fix for the vulnerability.

Google said it notified the affected company and law enforcement and was able to disrupt the operation before it caused any damage. But as it traced the hackers’ footprints, it found evidence they had used an AI large language model — the same technology that powers popular chatbots — to discover the vulnerability.

Google didn’t reveal which AI model was used in the cyberattack, only that it was most likely not Google’s own Gemini or Anthropic’s Claude Mythos. Google also didn’t reveal which group it suspected in the attack but said there was no evidence it was tied to an adversarial government, though the company said groups tied to China and North Korea have been exploring similar techniques.

Hultquist said that compared with government spies who typically work slowly and quietly, criminal hackers have some of the most to gain from AI’s “tremendous capability for speed” in finding and weaponizing security bugs.

“There’s a race between you and them to stop them before they can essentially get whatever data they need to extort you with, or launch ransomware,” he said in an interview. “AI is going to be a huge advantage because they can move a lot faster.”

Anthropic’s Mythos has sparked a panic and call for regulation

Trump’s Commerce Department announced last week that it signed new agreements with Google, Microsoft and Elon Musk’s xAI to evaluate their most powerful AI models before their public release, building on previous agreements the Biden administration made with Anthropic and ChatGPT maker OpenAI. But the announcement later disappeared from the Commerce Department website.

It was the latest example of jumbled signals from the Trump administration in the month since Anthropic announced a new model it called Mythos that it said was so “strikingly capable” at hacking and cybersecurity work that it could only release it to a small group of trusted organizations.

Anthropic created an initiative called Project Glasswing bringing together tech giants including Amazon, Apple, Google and Microsoft, along with other companies like JPMorgan Chase, in hopes of securing the world’s critical software from “severe” fallout that the new model could pose to public safety, national security and the economy. But its relationship with the U.S. government was complicated by a public and legal fight with the Pentagon and Trump himself over military use of its AI technology.

Its top rival, OpenAI, has since introduced a similar model. The company said Friday it was releasing a specialized cybersecurity version of ChatGPT that would only be available to “defenders responsible for securing critical infrastructure” to help them find and patch vulnerabilities in their code.

Ball said he’s optimistic that, over the long term, AI tools that are increasingly good at coding will make us safer from the routine cyberattacks afflicting hospitals, schools and other organizations. In the meantime, however, he said there are “untold trillions of lines of software code” supporting the world’s computing systems that are at risk if AI tools are unleashed to exploit all of their bugs.

It could take years to harden all of that software — a process that Ball believes would be aided by coordination from the U.S. government.

In the meantime, Ball predicts a “transitional period” where cybersecurity risks rise significantly and “the world might actually be more dangerous.”

Report Error Submit a Tip

More Stories

Improving building standards

Jean Clipsham 4 minute read 2:00 AM CDT

As I was working in my garden today, I was thinking that, while I still enjoy it, I am starting to wonder how much longer I will be able to care for a house and a yard. Like many my age, I have been thinking about the condominium option here in Winnipeg.

I am a mother and a grandmother and I am also very concerned about climate change and the need to recognize that our emissions from coal, oil, and gas are warming the Earth. As a climate activist, I do not want to pollute. Yet as a condo purchaser, I would have no control over how the building is insulated, heated and cooled or how much energy it would take to do so.

When I moved to Winnipeg four years ago, I intended to buy a house and install a heat pump, which heats and cools a home using electricity only.

Before that purchase, I phoned Manitoba Hydro and was advised to buy a home built after 1985, when national standards were upgraded to require better insulation. That was no trouble for me, given I had already moved from a 1960s house into a new house in 1989 and even though the new home was larger, our gas bill was cut in half because of the added insulation.

Men accused in commercial break-in spree were wearing ankle bracelets

Erik Pindera 5 minute read Preview

Men accused in commercial break-in spree were wearing ankle bracelets

Erik Pindera 5 minute read Updated: Yesterday at 6:28 PM CDT

Two men in electric ankle bracelets who were being monitored by justice officials have been accused in a two-month spree of commercial break-ins, vehicle thefts and other property crimes.

City police have charged one of the suspects and are searching for the second.

About $140,000 worth of property, including trailers, lawn equipment, motorcycles and bicycles, was reported stolen in 13 incidents in Winnipeg and the Rural Municipality of Headingley between April 20 and June 28, the Winnipeg Police Service said.

Both suspects were wearing electronic monitoring bracelets during that time.

Read
Updated: Yesterday at 6:28 PM CDT

Trustees call for e-scooter safety education

Maggie Macintosh 4 minute read Preview

Trustees call for e-scooter safety education

Maggie Macintosh 4 minute read Yesterday at 6:00 AM CDT

School trustees are calling on the province to bolster public education around e-bike and e-scooter safety ahead of back-to-school season.

The Manitoba School Boards Association brought members’ concerns about a growing number of students using electronic devices to get to and from classes to the education minister’s office this month.

“There’s a concerning lack of safety knowledge on the part of Manitoba youth,” executive director Alan Campbell said.

Campbell, a long-time trustee in the Interlake School Division, resigned from elected office this summer to run the association that mobilizes school boards and provides them with labour relations support.

Read
Yesterday at 6:00 AM CDT

‘You vote with your bike’: cyclists celebrate freedoms, call for increased safety

Maggie Macintosh 5 minute read Preview

‘You vote with your bike’: cyclists celebrate freedoms, call for increased safety

Maggie Macintosh 5 minute read Updated: Yesterday at 9:24 AM CDT

Patty Wiens got dressed up in her sparkly, hot pink cowboy boots to pedal and talk politics with more than 100 other people on Sunday.

The founder of Winnipeg’s Fancy Women Bike Ride called on attendees of the 2026 event to ask candidates in the upcoming civic election — a half-dozen of whom were in attendance — about their active transportation platforms.

“We’re here today, in an election year, to remind you that you vote with your bike,” Wiens told a crowd of nearly 120 cyclists gathered on the legislature grounds for the group ride.

“When (city council) candidates come to your door and ask what’s important to you, you’re going to say, ‘I want to ride my bike safely in the city. What are you going to do about it?’”

Read
Updated: Yesterday at 9:24 AM CDT

A grand jeté of climate-change denial

Gwynne Dyer 5 minute read Preview

A grand jeté of climate-change denial

Gwynne Dyer 5 minute read 2:00 AM CDT

The first hurricane to hit Hawaii in 34 years. The Mediterranean on fire from Spain to Greece. ‘Heat domes’ one after another for months on end in Europe and North America. Thousands of excess deaths. A record El Niño piled on top of an average global temperature up from +1.2 C five years ago. Predicted high for this year: +1.7 C.

Surely they’ll get it now, you think — but no, they won’t. It once seemed sensible to think that when the climate damage gets bad enough and the trend line becomes impossible to ignore, ‘they’ (meaning the climate change deniers and their fellow travellers) will finally accept that the threat is real and urgent action is necessary.

A few of them will, but most will not.

It is becoming clear that as the old position of flat disbelief in climate science becomes untenable, the preferred response among former deniers is to admit that climate change is big, dangerous and already well underway — but to insist that it is already too late and nothing can be done about it now.

Read
2:00 AM CDT

Paralyzed foster girl has system under a microscope

Chris Kitching 6 minute read Preview

Paralyzed foster girl has system under a microscope

Chris Kitching 6 minute read 2:00 AM CDT

An internal investigation by Manitoba’s Families Department is nearly complete in the case of a six-year-old girl who is paralyzed after being assaulted by her foster mother in Winnipeg.

The review by child-welfare officials is intended to prevent similar incidents, but it’s unlikely the public will learn the findings or recommendations.

“We’re working closely with the (child and family services) authority to make sure that every recommendation is taken seriously and implemented,” Families Minister Nahanni Fontaine said Monday.

“They’re important (investigations) because they help us identify what went wrong so we can make those changes to ensure something like this tragedy never happens again.”

Read
2:00 AM CDT