AI just crossed a red line in cybersecurity — and this time, it's officially confirmed.

For the first time in history, a criminal threat actor used artificial intelligence to develop a zero-day exploit. This isn't a prediction or a war game scenario. It happened — and Mandiant's Google Threat Intelligence Group (GTIG) documented it in May 2026.

The target? A 2FA bypass in a widely used open-source web administration tool. How did researchers identify AI involvement? The code left clear fingerprints: educational-style docstrings, a hallucinated CVSS score embedded in the comments, and textbook-structured exploit logic. Classic signatures of an AI-assisted workflow. The campaign was disrupted before mass exploitation — but the precedent has been set, and it cannot be undone.

And it doesn't stop there.

PRC-linked threat group UNC2814 was caught using AI models as "expert-persona security auditors" — systematically feeding them TP-Link firmware and OFTP protocol implementations to identify vulnerabilities at a scale no human team could match.

DPRK-linked APT45 sent thousands of repetitive prompts to LLMs to recursively analyze CVEs and validate proof-of-concept exploits — essentially running an AI-powered automated red team 24 hours a day, without rest and without human bottlenecks.

But the most alarming discovery? An Android backdoor named PROMPTSPY — containing a module called GeminiAutomationAgent — that actively calls Google's Gemini 2.5 Flash API to autonomously interact with compromised devices. It serializes the full UI hierarchy of the infected phone and issues tap, swipe, and input commands — with zero human involvement.

Let that sink in: AI is now autonomously orchestrating post-exploitation operations on compromised devices.

What does this mean for defenders?

Threat actors no longer need elite developers to write exploits. AI dramatically lowers the barrier to entry. The speed and volume of zero-day discovery will accelerate — faster than most organizations can patch. Autonomous post-compromise behavior means dwell time shrinks and damage happens before SOC teams can respond. Detection models trained on human-written malware signatures need urgent updates to catch AI-generated patterns.

We have spent years debating whether AI would fundamentally change the threat landscape. That debate is now closed.

The real question is: how fast can defenders adopt AI with the same urgency as attackers?

Because right now, the gap is real — and closing it is not optional.

Patch aggressively. Hunt proactively. Retrain your models. The AI-powered offensive era has officially begun.

Sources: Mandiant/GTIG (May 2026), Google Cloud Threat Intelligence, Digital Forensics Magazine (June 12, 2026)

Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.