{"id":12590,"date":"2026-05-04T10:03:41","date_gmt":"2026-05-04T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/04\/threat-actors-use-ai-to-automate-0-day-discovery-and-exploitation-at-machine-speed\/"},"modified":"2026-05-04T10:03:41","modified_gmt":"2026-05-04T10:03:41","slug":"threat-actors-use-ai-to-automate-0-day-discovery-and-exploitation-at-machine-speed","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/04\/threat-actors-use-ai-to-automate-0-day-discovery-and-exploitation-at-machine-speed\/","title":{"rendered":"Threat Actors Use AI to Automate 0-Day Discovery and Exploitation at Machine Speed"},"content":{"rendered":"<p>    Threat Actors Use AI to Automate 0-Day Discovery and Exploitation at Machine Speed<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The way cyberattacks are launched has fundamentally changed. Threat actors are no longer spending months hunting for software flaws by hand. <\/p>\n<p>With artificial intelligence in their toolkit, they can now discover and exploit zero-day vulnerabilities in minutes, placing organizations across every sector at serious risk.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/eb20a683-b053-44a7-b14b-164aa7b63a23\/Threat-Actors-Use-AI-to-Automate-0-Day-Discovery-and-Exploitation-at-Machine-Speed.pdf?AWSAccessKeyId=ASIA2F3EMEYETAXN5S2V&amp;Signature=OI3LF654uBWdHeeGTiDX7ZsLgF4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICVWg51IxXpvNrlajcHaezHaCU4X4k3qlYKyl6qloY0fAiEAgLMBAkPruuLYuOZmAPkeycdYZTxvpdxRGCEAfUyAoMEq8wQIZxABGgw2OTk3NTMzMDk3MDUiDCzQ9uI2IgU2bPo4WSrQBGuIhrHz7YCcyGquoxZbv6SFGJ6xyEX7JS2hlyBN22GAAy97LGG9qWVvymPm4Fc2fCnVB2Xcbg0JqWemTp57ia7%2FrVJLmr2%2BCXfXz4fw0Xjr1rbdjbO3WyIes%2ByBfo6OqjEv9r9DvEJkyoY5Uft9TcVLFqLLr9mUdTCsQvbkou3NNmQA7vs9SwEvhZ%2BHNWQPasO1MhXrOnGS4MVjYc7NWN%2FdJEuGaB1%2F0VM02JtsczuEli5bdblHdhor5ogbbDiXCxUBNc9O1Xog0d3XUg2oUiZi3Iqzdx8qe7D9ca9e3rBiUnSGUHOAsnEbIBnj0YI%2BT1NeFYhEjPzb1heNYyMNPVWDWY8eCAjgZL3u0jXGKiUYlxLMYxZSGYEqK38%2FwvupjDpi7Pm0g7STTj37kCxv5aecPJ3bqoBDyHu5rdXMTgYrqjdctUSG2BRjjAanh5pxBn%2B5JV9VwSjzh65MGQor%2F3g4TvAF5YxdUvyLOeQKuTaNwWy%2FhsOQVQ03pZT7YKKjdDGsp3D%2Fmhuxq29kcQ5GhlhwPjduHhtgbp7vCvikAdSPH%2FIaxFc%2FyxoI8zFvE45guDcZIlUV6mUotOmZXHhZQzH%2BooY9Ja%2Fz74IB7hU3ScJUUajbI5EUAB1bdrZhLSkqEbu5rDhW5NXC6e3r89C34VCaGQcg5rISK1s3eCYA%2BibNPNIZbs21%2BCgnPo0M%2FWdFha9pujzcONmdSvCz3Q56qpFFKKpI1lI8DYy2WX%2Bpev3pU5qGodhJL1Dej7omsUwBMkrGhGtNVy7KhDSb7XGtaYMwu%2B%2FgzwY6mAEdLdijxYE32uWx2w3jhuh1uKZdJH1OxSVThQ2hWuVLLxSknN5LdS4%2FRjo%2FrvIyFC9LgsTJBMNUrB1gqRhyxmDhfjv03BN6%2FzOFNPln0e%2BYCHs0vX2l4KOniUqCb5QTflz2DiI3L5Hz6NgFR%2B%2BgZp247gS7gVwWP%2BtSDRGcZyQvsSYu4OY80P0cfBTy3RCyAi0ROsk9QVo7vw%3D%3D&amp;Expires=1777877904\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>For years, finding a zero-day required deep technical skill, long research cycles, and heavy resources. <\/p>\n<p>Only well-funded nation-state groups or elite crews could do it consistently. That barrier no longer holds. <\/p>\n<p>AI has made zero-day discovery faster, cheaper, and accessible to a wider range of attackers, including those without coding knowledge. <\/p>\n<p>An attacker today gives an AI model a target, and the model independently scans the network, hunts for weaknesses, attempts exploits, and switches paths when one fails. <\/p>\n<p>Through standards like the Model Context Protocol, <a href=\"https:\/\/cybersecuritynews.com\/hackers-using-ai-agents\/\" id=\"91523\" target=\"_blank\" rel=\"noreferrer noopener\">AI agents<\/a> connect to real environments and execute full attack chains with minimal human input.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/eb20a683-b053-44a7-b14b-164aa7b63a23\/Threat-Actors-Use-AI-to-Automate-0-Day-Discovery-and-Exploitation-at-Machine-Speed.pdf?AWSAccessKeyId=ASIA2F3EMEYETAXN5S2V&amp;Signature=OI3LF654uBWdHeeGTiDX7ZsLgF4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICVWg51IxXpvNrlajcHaezHaCU4X4k3qlYKyl6qloY0fAiEAgLMBAkPruuLYuOZmAPkeycdYZTxvpdxRGCEAfUyAoMEq8wQIZxABGgw2OTk3NTMzMDk3MDUiDCzQ9uI2IgU2bPo4WSrQBGuIhrHz7YCcyGquoxZbv6SFGJ6xyEX7JS2hlyBN22GAAy97LGG9qWVvymPm4Fc2fCnVB2Xcbg0JqWemTp57ia7%2FrVJLmr2%2BCXfXz4fw0Xjr1rbdjbO3WyIes%2ByBfo6OqjEv9r9DvEJkyoY5Uft9TcVLFqLLr9mUdTCsQvbkou3NNmQA7vs9SwEvhZ%2BHNWQPasO1MhXrOnGS4MVjYc7NWN%2FdJEuGaB1%2F0VM02JtsczuEli5bdblHdhor5ogbbDiXCxUBNc9O1Xog0d3XUg2oUiZi3Iqzdx8qe7D9ca9e3rBiUnSGUHOAsnEbIBnj0YI%2BT1NeFYhEjPzb1heNYyMNPVWDWY8eCAjgZL3u0jXGKiUYlxLMYxZSGYEqK38%2FwvupjDpi7Pm0g7STTj37kCxv5aecPJ3bqoBDyHu5rdXMTgYrqjdctUSG2BRjjAanh5pxBn%2B5JV9VwSjzh65MGQor%2F3g4TvAF5YxdUvyLOeQKuTaNwWy%2FhsOQVQ03pZT7YKKjdDGsp3D%2Fmhuxq29kcQ5GhlhwPjduHhtgbp7vCvikAdSPH%2FIaxFc%2FyxoI8zFvE45guDcZIlUV6mUotOmZXHhZQzH%2BooY9Ja%2Fz74IB7hU3ScJUUajbI5EUAB1bdrZhLSkqEbu5rDhW5NXC6e3r89C34VCaGQcg5rISK1s3eCYA%2BibNPNIZbs21%2BCgnPo0M%2FWdFha9pujzcONmdSvCz3Q56qpFFKKpI1lI8DYy2WX%2Bpev3pU5qGodhJL1Dej7omsUwBMkrGhGtNVy7KhDSb7XGtaYMwu%2B%2FgzwY6mAEdLdijxYE32uWx2w3jhuh1uKZdJH1OxSVThQ2hWuVLLxSknN5LdS4%2FRjo%2FrvIyFC9LgsTJBMNUrB1gqRhyxmDhfjv03BN6%2FzOFNPln0e%2BYCHs0vX2l4KOniUqCb5QTflz2DiI3L5Hz6NgFR%2B%2BgZp247gS7gVwWP%2BtSDRGcZyQvsSYu4OY80P0cfBTy3RCyAi0ROsk9QVo7vw%3D%3D&amp;Expires=1777877904\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Actor activities monitored at Cyberthint indicate that discovering zero-days is no longer a specialized task taking months, but has become a process that can be automated in minutes. <\/p>\n<p><a href=\"https:\/\/cyberthint.io\/the-new-operational-model-of-threat-actors-the-0-day-race-in-the-shadow-of-ai\/\" id=\"https:\/\/cyberthint.io\/the-new-operational-model-of-threat-actors-the-0-day-race-in-the-shadow-of-ai\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cyberthint analysts and researchers identified this structural shift<\/a> in late 2024, noting that AI is now operating not just as an assistant but as an active attacker. Tasks once requiring a ten-person red team for weeks now take just hours.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/eb20a683-b053-44a7-b14b-164aa7b63a23\/Threat-Actors-Use-AI-to-Automate-0-Day-Discovery-and-Exploitation-at-Machine-Speed.pdf?AWSAccessKeyId=ASIA2F3EMEYETAXN5S2V&amp;Signature=OI3LF654uBWdHeeGTiDX7ZsLgF4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICVWg51IxXpvNrlajcHaezHaCU4X4k3qlYKyl6qloY0fAiEAgLMBAkPruuLYuOZmAPkeycdYZTxvpdxRGCEAfUyAoMEq8wQIZxABGgw2OTk3NTMzMDk3MDUiDCzQ9uI2IgU2bPo4WSrQBGuIhrHz7YCcyGquoxZbv6SFGJ6xyEX7JS2hlyBN22GAAy97LGG9qWVvymPm4Fc2fCnVB2Xcbg0JqWemTp57ia7%2FrVJLmr2%2BCXfXz4fw0Xjr1rbdjbO3WyIes%2ByBfo6OqjEv9r9DvEJkyoY5Uft9TcVLFqLLr9mUdTCsQvbkou3NNmQA7vs9SwEvhZ%2BHNWQPasO1MhXrOnGS4MVjYc7NWN%2FdJEuGaB1%2F0VM02JtsczuEli5bdblHdhor5ogbbDiXCxUBNc9O1Xog0d3XUg2oUiZi3Iqzdx8qe7D9ca9e3rBiUnSGUHOAsnEbIBnj0YI%2BT1NeFYhEjPzb1heNYyMNPVWDWY8eCAjgZL3u0jXGKiUYlxLMYxZSGYEqK38%2FwvupjDpi7Pm0g7STTj37kCxv5aecPJ3bqoBDyHu5rdXMTgYrqjdctUSG2BRjjAanh5pxBn%2B5JV9VwSjzh65MGQor%2F3g4TvAF5YxdUvyLOeQKuTaNwWy%2FhsOQVQ03pZT7YKKjdDGsp3D%2Fmhuxq29kcQ5GhlhwPjduHhtgbp7vCvikAdSPH%2FIaxFc%2FyxoI8zFvE45guDcZIlUV6mUotOmZXHhZQzH%2BooY9Ja%2Fz74IB7hU3ScJUUajbI5EUAB1bdrZhLSkqEbu5rDhW5NXC6e3r89C34VCaGQcg5rISK1s3eCYA%2BibNPNIZbs21%2BCgnPo0M%2FWdFha9pujzcONmdSvCz3Q56qpFFKKpI1lI8DYy2WX%2Bpev3pU5qGodhJL1Dej7omsUwBMkrGhGtNVy7KhDSb7XGtaYMwu%2B%2FgzwY6mAEdLdijxYE32uWx2w3jhuh1uKZdJH1OxSVThQ2hWuVLLxSknN5LdS4%2FRjo%2FrvIyFC9LgsTJBMNUrB1gqRhyxmDhfjv03BN6%2FzOFNPln0e%2BYCHs0vX2l4KOniUqCb5QTflz2DiI3L5Hz6NgFR%2B%2BgZp247gS7gVwWP%2BtSDRGcZyQvsSYu4OY80P0cfBTy3RCyAi0ROsk9QVo7vw%3D%3D&amp;Expires=1777877904\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>In February 2025, MITRE expanded its ATT&amp;CK framework to cover AI-orchestrated operations, confirming that this threat category has matured into a serious industry-wide concern.<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/eb20a683-b053-44a7-b14b-164aa7b63a23\/Threat-Actors-Use-AI-to-Automate-0-Day-Discovery-and-Exploitation-at-Machine-Speed.pdf?AWSAccessKeyId=ASIA2F3EMEYETAXN5S2V&amp;Signature=OI3LF654uBWdHeeGTiDX7ZsLgF4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICVWg51IxXpvNrlajcHaezHaCU4X4k3qlYKyl6qloY0fAiEAgLMBAkPruuLYuOZmAPkeycdYZTxvpdxRGCEAfUyAoMEq8wQIZxABGgw2OTk3NTMzMDk3MDUiDCzQ9uI2IgU2bPo4WSrQBGuIhrHz7YCcyGquoxZbv6SFGJ6xyEX7JS2hlyBN22GAAy97LGG9qWVvymPm4Fc2fCnVB2Xcbg0JqWemTp57ia7%2FrVJLmr2%2BCXfXz4fw0Xjr1rbdjbO3WyIes%2ByBfo6OqjEv9r9DvEJkyoY5Uft9TcVLFqLLr9mUdTCsQvbkou3NNmQA7vs9SwEvhZ%2BHNWQPasO1MhXrOnGS4MVjYc7NWN%2FdJEuGaB1%2F0VM02JtsczuEli5bdblHdhor5ogbbDiXCxUBNc9O1Xog0d3XUg2oUiZi3Iqzdx8qe7D9ca9e3rBiUnSGUHOAsnEbIBnj0YI%2BT1NeFYhEjPzb1heNYyMNPVWDWY8eCAjgZL3u0jXGKiUYlxLMYxZSGYEqK38%2FwvupjDpi7Pm0g7STTj37kCxv5aecPJ3bqoBDyHu5rdXMTgYrqjdctUSG2BRjjAanh5pxBn%2B5JV9VwSjzh65MGQor%2F3g4TvAF5YxdUvyLOeQKuTaNwWy%2FhsOQVQ03pZT7YKKjdDGsp3D%2Fmhuxq29kcQ5GhlhwPjduHhtgbp7vCvikAdSPH%2FIaxFc%2FyxoI8zFvE45guDcZIlUV6mUotOmZXHhZQzH%2BooY9Ja%2Fz74IB7hU3ScJUUajbI5EUAB1bdrZhLSkqEbu5rDhW5NXC6e3r89C34VCaGQcg5rISK1s3eCYA%2BibNPNIZbs21%2BCgnPo0M%2FWdFha9pujzcONmdSvCz3Q56qpFFKKpI1lI8DYy2WX%2Bpev3pU5qGodhJL1Dej7omsUwBMkrGhGtNVy7KhDSb7XGtaYMwu%2B%2FgzwY6mAEdLdijxYE32uWx2w3jhuh1uKZdJH1OxSVThQ2hWuVLLxSknN5LdS4%2FRjo%2FrvIyFC9LgsTJBMNUrB1gqRhyxmDhfjv03BN6%2FzOFNPln0e%2BYCHs0vX2l4KOniUqCb5QTflz2DiI3L5Hz6NgFR%2B%2BgZp247gS7gVwWP%2BtSDRGcZyQvsSYu4OY80P0cfBTy3RCyAi0ROsk9QVo7vw%3D%3D&amp;Expires=1777877904\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"ai-driven-espionage-and-the-gamechange-campaign\"><strong>AI-Driven Espionage and the GAMECHANGE Campaign<\/strong><\/h2>\n<p>The most striking case study in this space is GAMECHANGE, the first documented instance of AI-orchestrated espionage. <\/p>\n<p>Identified in mid-September 2024 and assessed with high confidence as a Chinese state-backed operation, GAMECHANGE targeted roughly 70 global entities including technology companies, financial institutions, and government agencies, with four organizations successfully compromised. <\/p>\n<p>The malware was written in Python, compiled into a Windows PE file using PyInstaller, and delivered from compromised email accounts impersonating Ukrainian ministry representatives.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/eb20a683-b053-44a7-b14b-164aa7b63a23\/Threat-Actors-Use-AI-to-Automate-0-Day-Discovery-and-Exploitation-at-Machine-Speed.pdf?AWSAccessKeyId=ASIA2F3EMEYETAXN5S2V&amp;Signature=OI3LF654uBWdHeeGTiDX7ZsLgF4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICVWg51IxXpvNrlajcHaezHaCU4X4k3qlYKyl6qloY0fAiEAgLMBAkPruuLYuOZmAPkeycdYZTxvpdxRGCEAfUyAoMEq8wQIZxABGgw2OTk3NTMzMDk3MDUiDCzQ9uI2IgU2bPo4WSrQBGuIhrHz7YCcyGquoxZbv6SFGJ6xyEX7JS2hlyBN22GAAy97LGG9qWVvymPm4Fc2fCnVB2Xcbg0JqWemTp57ia7%2FrVJLmr2%2BCXfXz4fw0Xjr1rbdjbO3WyIes%2ByBfo6OqjEv9r9DvEJkyoY5Uft9TcVLFqLLr9mUdTCsQvbkou3NNmQA7vs9SwEvhZ%2BHNWQPasO1MhXrOnGS4MVjYc7NWN%2FdJEuGaB1%2F0VM02JtsczuEli5bdblHdhor5ogbbDiXCxUBNc9O1Xog0d3XUg2oUiZi3Iqzdx8qe7D9ca9e3rBiUnSGUHOAsnEbIBnj0YI%2BT1NeFYhEjPzb1heNYyMNPVWDWY8eCAjgZL3u0jXGKiUYlxLMYxZSGYEqK38%2FwvupjDpi7Pm0g7STTj37kCxv5aecPJ3bqoBDyHu5rdXMTgYrqjdctUSG2BRjjAanh5pxBn%2B5JV9VwSjzh65MGQor%2F3g4TvAF5YxdUvyLOeQKuTaNwWy%2FhsOQVQ03pZT7YKKjdDGsp3D%2Fmhuxq29kcQ5GhlhwPjduHhtgbp7vCvikAdSPH%2FIaxFc%2FyxoI8zFvE45guDcZIlUV6mUotOmZXHhZQzH%2BooY9Ja%2Fz74IB7hU3ScJUUajbI5EUAB1bdrZhLSkqEbu5rDhW5NXC6e3r89C34VCaGQcg5rISK1s3eCYA%2BibNPNIZbs21%2BCgnPo0M%2FWdFha9pujzcONmdSvCz3Q56qpFFKKpI1lI8DYy2WX%2Bpev3pU5qGodhJL1Dej7omsUwBMkrGhGtNVy7KhDSb7XGtaYMwu%2B%2FgzwY6mAEdLdijxYE32uWx2w3jhuh1uKZdJH1OxSVThQ2hWuVLLxSknN5LdS4%2FRjo%2FrvIyFC9LgsTJBMNUrB1gqRhyxmDhfjv03BN6%2FzOFNPln0e%2BYCHs0vX2l4KOniUqCb5QTflz2DiI3L5Hz6NgFR%2B%2BgZp247gS7gVwWP%2BtSDRGcZyQvsSYu4OY80P0cfBTy3RCyAi0ROsk9QVo7vw%3D%3D&amp;Expires=1777877904\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgfwijPMHKSFv_uZbo7xF8uH8z0dtoN0x8hbMRwk-S7ILNT0ukhMS0LAX0jKksL76lESON6IhnJzrUJ4yP39JrPFAnAfphBNZITQ4TNaP96CLVWn5YU561cH7CsVlY1HIqDQqF9fnz3vn0DnArG_2ytGsv1736vp8PqWa5LVKc_uiE-PjFt8OzK4lyVbGI\/s16000\/GTG-1002%27s%2520AI-orchestrated%2520espionage%2520%28Source%2520-%2520Cyberthint%29.webp?ssl=1\" alt=\"GTG-1002's AI-orchestrated espionage (Source - Cyberthint)\"><figcaption class=\"wp-element-caption\">GTG-1002\u2019s AI-orchestrated espionage (Source \u2013 Cyberthint)<\/figcaption><\/figure>\n<\/div>\n<p>What set GAMECHANGE apart was that its instructions were not hardcoded into the binary. Instead, it sent queries to Alibaba\u2019s Qwen-Coder model via the Hugging Face API, generating commands to execute in real time. <\/p>\n<p>It embedded unique API tokens to resist blacklisting, collected hardware, process, network, and Active Directory data, and recursively copied Office documents and PDFs. <\/p>\n<p>MITRE\u2019s Black Hat analysis described GAMECHANGE as a pilot program testing LLM capabilities before broader deployment.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/eb20a683-b053-44a7-b14b-164aa7b63a23\/Threat-Actors-Use-AI-to-Automate-0-Day-Discovery-and-Exploitation-at-Machine-Speed.pdf?AWSAccessKeyId=ASIA2F3EMEYETAXN5S2V&amp;Signature=OI3LF654uBWdHeeGTiDX7ZsLgF4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICVWg51IxXpvNrlajcHaezHaCU4X4k3qlYKyl6qloY0fAiEAgLMBAkPruuLYuOZmAPkeycdYZTxvpdxRGCEAfUyAoMEq8wQIZxABGgw2OTk3NTMzMDk3MDUiDCzQ9uI2IgU2bPo4WSrQBGuIhrHz7YCcyGquoxZbv6SFGJ6xyEX7JS2hlyBN22GAAy97LGG9qWVvymPm4Fc2fCnVB2Xcbg0JqWemTp57ia7%2FrVJLmr2%2BCXfXz4fw0Xjr1rbdjbO3WyIes%2ByBfo6OqjEv9r9DvEJkyoY5Uft9TcVLFqLLr9mUdTCsQvbkou3NNmQA7vs9SwEvhZ%2BHNWQPasO1MhXrOnGS4MVjYc7NWN%2FdJEuGaB1%2F0VM02JtsczuEli5bdblHdhor5ogbbDiXCxUBNc9O1Xog0d3XUg2oUiZi3Iqzdx8qe7D9ca9e3rBiUnSGUHOAsnEbIBnj0YI%2BT1NeFYhEjPzb1heNYyMNPVWDWY8eCAjgZL3u0jXGKiUYlxLMYxZSGYEqK38%2FwvupjDpi7Pm0g7STTj37kCxv5aecPJ3bqoBDyHu5rdXMTgYrqjdctUSG2BRjjAanh5pxBn%2B5JV9VwSjzh65MGQor%2F3g4TvAF5YxdUvyLOeQKuTaNwWy%2FhsOQVQ03pZT7YKKjdDGsp3D%2Fmhuxq29kcQ5GhlhwPjduHhtgbp7vCvikAdSPH%2FIaxFc%2FyxoI8zFvE45guDcZIlUV6mUotOmZXHhZQzH%2BooY9Ja%2Fz74IB7hU3ScJUUajbI5EUAB1bdrZhLSkqEbu5rDhW5NXC6e3r89C34VCaGQcg5rISK1s3eCYA%2BibNPNIZbs21%2BCgnPo0M%2FWdFha9pujzcONmdSvCz3Q56qpFFKKpI1lI8DYy2WX%2Bpev3pU5qGodhJL1Dej7omsUwBMkrGhGtNVy7KhDSb7XGtaYMwu%2B%2FgzwY6mAEdLdijxYE32uWx2w3jhuh1uKZdJH1OxSVThQ2hWuVLLxSknN5LdS4%2FRjo%2FrvIyFC9LgsTJBMNUrB1gqRhyxmDhfjv03BN6%2FzOFNPln0e%2BYCHs0vX2l4KOniUqCb5QTflz2DiI3L5Hz6NgFR%2B%2BgZp247gS7gVwWP%2BtSDRGcZyQvsSYu4OY80P0cfBTy3RCyAi0ROsk9QVo7vw%3D%3D&amp;Expires=1777877904\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh-ZBx9JHYdJpGxzX6lS7jT-6rH1jxNYi8DhAhhpBPj8Ab7e4XMvowLY1tD_3QWqNebgKJ4m_f-0UCKNQ-Ynz7KFsdy_0-es_tuVoODZds4p8PFXS3TfjYZNqaIlbagpXxKj0n1RJ1AMGDfdbVv3FP-F4w3FBro2eEpqURPtoFB5JYf7w9IfDGsk0CzrZo\/s16000\/Fake%2520Ukrainian%2520ministry%2520representatives%2520%28Source%2520-%2520Cyberthint%29.webp?ssl=1\" alt=\"Fake Ukrainian ministry representatives (Source - Cyberthint)\"><figcaption class=\"wp-element-caption\">Fake Ukrainian ministry representatives (Source \u2013 Cyberthint)<\/figcaption><\/figure>\n<\/div>\n<p>Two other experimental AI-powered malware families were also documented. MalTerminal, the earliest known malware that generates malicious payloads at runtime, was presented by SentinelLABS at LABScon 2024. <\/p>\n<p>When run, it offered a choice between ransomware or a reverse shell, sent requests to a GPT-4 endpoint, and generated encryption and exfiltration code in memory without writing to disk. <\/p>\n<p>JSOUTFMUT, discovered by GTID in June 2024, was a VBScript dropper that received its mutations from an external LLM. <\/p>\n<p>Its Thinking Robot module queried the Gemini Flash API for new obfuscation techniques, generating a fresh variant every hour and copying itself to removable drives and network shares.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/eb20a683-b053-44a7-b14b-164aa7b63a23\/Threat-Actors-Use-AI-to-Automate-0-Day-Discovery-and-Exploitation-at-Machine-Speed.pdf?AWSAccessKeyId=ASIA2F3EMEYETAXN5S2V&amp;Signature=OI3LF654uBWdHeeGTiDX7ZsLgF4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICVWg51IxXpvNrlajcHaezHaCU4X4k3qlYKyl6qloY0fAiEAgLMBAkPruuLYuOZmAPkeycdYZTxvpdxRGCEAfUyAoMEq8wQIZxABGgw2OTk3NTMzMDk3MDUiDCzQ9uI2IgU2bPo4WSrQBGuIhrHz7YCcyGquoxZbv6SFGJ6xyEX7JS2hlyBN22GAAy97LGG9qWVvymPm4Fc2fCnVB2Xcbg0JqWemTp57ia7%2FrVJLmr2%2BCXfXz4fw0Xjr1rbdjbO3WyIes%2ByBfo6OqjEv9r9DvEJkyoY5Uft9TcVLFqLLr9mUdTCsQvbkou3NNmQA7vs9SwEvhZ%2BHNWQPasO1MhXrOnGS4MVjYc7NWN%2FdJEuGaB1%2F0VM02JtsczuEli5bdblHdhor5ogbbDiXCxUBNc9O1Xog0d3XUg2oUiZi3Iqzdx8qe7D9ca9e3rBiUnSGUHOAsnEbIBnj0YI%2BT1NeFYhEjPzb1heNYyMNPVWDWY8eCAjgZL3u0jXGKiUYlxLMYxZSGYEqK38%2FwvupjDpi7Pm0g7STTj37kCxv5aecPJ3bqoBDyHu5rdXMTgYrqjdctUSG2BRjjAanh5pxBn%2B5JV9VwSjzh65MGQor%2F3g4TvAF5YxdUvyLOeQKuTaNwWy%2FhsOQVQ03pZT7YKKjdDGsp3D%2Fmhuxq29kcQ5GhlhwPjduHhtgbp7vCvikAdSPH%2FIaxFc%2FyxoI8zFvE45guDcZIlUV6mUotOmZXHhZQzH%2BooY9Ja%2Fz74IB7hU3ScJUUajbI5EUAB1bdrZhLSkqEbu5rDhW5NXC6e3r89C34VCaGQcg5rISK1s3eCYA%2BibNPNIZbs21%2BCgnPo0M%2FWdFha9pujzcONmdSvCz3Q56qpFFKKpI1lI8DYy2WX%2Bpev3pU5qGodhJL1Dej7omsUwBMkrGhGtNVy7KhDSb7XGtaYMwu%2B%2FgzwY6mAEdLdijxYE32uWx2w3jhuh1uKZdJH1OxSVThQ2hWuVLLxSknN5LdS4%2FRjo%2FrvIyFC9LgsTJBMNUrB1gqRhyxmDhfjv03BN6%2FzOFNPln0e%2BYCHs0vX2l4KOniUqCb5QTflz2DiI3L5Hz6NgFR%2B%2BgZp247gS7gVwWP%2BtSDRGcZyQvsSYu4OY80P0cfBTy3RCyAi0ROsk9QVo7vw%3D%3D&amp;Expires=1777877904\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Security teams must assume attackers now move at machine speed. Mean Time to Contain is more critical than Mean Time to Detect, since reactive strategies fail when attack speed outpaces patching. <\/p>\n<p>LotL surveillance should shift to the network layer, as classic IOCs are quickly becoming outdated. Anomaly-based signals like unexpected SMB admin share usage and high-entropy <a href=\"https:\/\/cybersecuritynews.com\/dns-queries-exploited-for-c2\/\" id=\"116541\" target=\"_blank\" rel=\"noreferrer noopener\">DNS queries<\/a> offer more persistent detection. <\/p>\n<p>AI API traffic should be added to monitoring lists, and YARA-based API key scanning alongside inspecting binaries for embedded JSON prompt structures are among the most effective ways to catch LLM-embedded malware. <\/p>\n<p>Placing artificial signals inside deception environments can also trigger false positives in attacker <a href=\"https:\/\/cybersecuritynews.com\/stride-gpt-ai-powered-tool\/\" id=\"99582\" target=\"_blank\" rel=\"noreferrer noopener\">AI models<\/a>. <\/p>\n<p>Ultimately, it is not the speed of patching but the speed of containing the breach that will decide the outcome.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/eb20a683-b053-44a7-b14b-164aa7b63a23\/Threat-Actors-Use-AI-to-Automate-0-Day-Discovery-and-Exploitation-at-Machine-Speed.pdf?AWSAccessKeyId=ASIA2F3EMEYETAXN5S2V&amp;Signature=OI3LF654uBWdHeeGTiDX7ZsLgF4%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEJ%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICVWg51IxXpvNrlajcHaezHaCU4X4k3qlYKyl6qloY0fAiEAgLMBAkPruuLYuOZmAPkeycdYZTxvpdxRGCEAfUyAoMEq8wQIZxABGgw2OTk3NTMzMDk3MDUiDCzQ9uI2IgU2bPo4WSrQBGuIhrHz7YCcyGquoxZbv6SFGJ6xyEX7JS2hlyBN22GAAy97LGG9qWVvymPm4Fc2fCnVB2Xcbg0JqWemTp57ia7%2FrVJLmr2%2BCXfXz4fw0Xjr1rbdjbO3WyIes%2ByBfo6OqjEv9r9DvEJkyoY5Uft9TcVLFqLLr9mUdTCsQvbkou3NNmQA7vs9SwEvhZ%2BHNWQPasO1MhXrOnGS4MVjYc7NWN%2FdJEuGaB1%2F0VM02JtsczuEli5bdblHdhor5ogbbDiXCxUBNc9O1Xog0d3XUg2oUiZi3Iqzdx8qe7D9ca9e3rBiUnSGUHOAsnEbIBnj0YI%2BT1NeFYhEjPzb1heNYyMNPVWDWY8eCAjgZL3u0jXGKiUYlxLMYxZSGYEqK38%2FwvupjDpi7Pm0g7STTj37kCxv5aecPJ3bqoBDyHu5rdXMTgYrqjdctUSG2BRjjAanh5pxBn%2B5JV9VwSjzh65MGQor%2F3g4TvAF5YxdUvyLOeQKuTaNwWy%2FhsOQVQ03pZT7YKKjdDGsp3D%2Fmhuxq29kcQ5GhlhwPjduHhtgbp7vCvikAdSPH%2FIaxFc%2FyxoI8zFvE45guDcZIlUV6mUotOmZXHhZQzH%2BooY9Ja%2Fz74IB7hU3ScJUUajbI5EUAB1bdrZhLSkqEbu5rDhW5NXC6e3r89C34VCaGQcg5rISK1s3eCYA%2BibNPNIZbs21%2BCgnPo0M%2FWdFha9pujzcONmdSvCz3Q56qpFFKKpI1lI8DYy2WX%2Bpev3pU5qGodhJL1Dej7omsUwBMkrGhGtNVy7KhDSb7XGtaYMwu%2B%2FgzwY6mAEdLdijxYE32uWx2w3jhuh1uKZdJH1OxSVThQ2hWuVLLxSknN5LdS4%2FRjo%2FrvIyFC9LgsTJBMNUrB1gqRhyxmDhfjv03BN6%2FzOFNPln0e%2BYCHs0vX2l4KOniUqCb5QTflz2DiI3L5Hz6NgFR%2B%2BgZp247gS7gVwWP%2BtSDRGcZyQvsSYu4OY80P0cfBTy3RCyAi0ROsk9QVo7vw%3D%3D&amp;Expires=1777877904\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-use-ai-to-automate-0-day-discovery\/\">Threat Actors Use AI to Automate 0-Day Discovery and Exploitation at Machine Speed<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-use-ai-to-automate-0-day-discovery\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Use AI to Automate 0-Day Discovery and Exploitation at Machine Speed The way cyberattacks are launched has fundamentally changed. Threat actors are no longer spending months hunting for software flaws by hand. With artificial intelligence in their toolkit, they can now discover and exploit zero-day vulnerabilities in minutes, placing organizations across every sector [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-12590","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12590"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12590"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12590\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}