What Happened
Google’s Threat Intelligence Group has published a stark assessment: AI-powered hacking has escalated from a nascent problem to an industrial-scale threat in just three months. The report reveals that criminal groups alongside state-linked actors from China, North Korea, and Russia are widely using commercial AI models — including Gemini, Claude, and OpenAI tools — to refine and scale up cyberattacks.
“There’s a misconception that the AI vulnerability race is imminent. The reality is that it’s already begun,” said John Hultquist, the group’s chief analyst. The report found that one criminal group was on the verge of leveraging a zero-day vulnerability for a mass exploitation campaign using an LLM — and that groups were experimenting with autonomous AI agents to accelerate attacks.
The UK’s AI Security Institute estimates that frontier cyber-offence capabilities are now doubling every four months, a pace that outstrips most organizations’ ability to patch and defend.
Source
📰 The Guardian — AI-powered hacking has exploded into industrial-scale threat, Google says
Why This Matters
This isn’t a theoretical warning anymore — it’s a field report. The asymmetry is brutal: attackers only need to find one flaw, while defenders must secure everything. AI dramatically tips that balance by letting relatively unsophisticated groups operate at the speed and scale previously reserved for well-funded state actors.
The mention of Anthropic’s withheld Mythos model adds another layer: if a commercially-accessible LLM can find zero-days in every major OS and browser, the offensive side of AI cybersecurity is already far ahead of the defensive one. Organizations need to assume their current patch cadence is inadequate and shift toward continuous, AI-assisted vulnerability management — because the attackers already have.
