All Reports

Google says hackers used AI to exploit ‘zero-day’ flaw - UPI.com

upi.comMay 11, 2026 at 06:54 PM122 views
D

Factual Misattribution

How They Deceive You

Propaganda

D

High-severity factual error misattributes 'AI-enabled malware such as PROMPTSPY' directly as Google's identified zero-day exploit, distorting the threat portrayal.

Main Device

Factual Misattribution

Falsely implies Google Threat Intelligence Group identified PROMPTSPY as the specific zero-day web admin tool exploit, rather than a separate AI malware example in broader trends.

Archetype

Mainstream cybersecurity alarmist

Amplifies AI hacking threats with sensational claims to stoke tech security fears, aligning with conventional industry hype around emerging tech risks.

Misattributes an AI malware example as the zero-day exploit per Google, hyping AI dangers while omitting the attack's foiled status and geopolitical context.

Writer's Worldview

Mainstream cybersecurity alarmist

2 findings · 2 omissions · 5 sources compared

What is your news hiding from you?

Same analysis. Any article. Completely free.

Narrative Analysis

Verdict: This UPI article delivers a solid, concise report on Google's May 2026 disclosure of hackers using AI to develop a novel zero-day exploit targeting a web admin tool, marking a cybersecurity first. However, it introduces a factual error by linking the threat to the unrelated PROMPTSPY malware and relies on unverified quotes, which muddle the details without undermining the core story.

Key Strengths

  • Accurate core facts: Correctly notes Google's identification of an AI-developed zero-day for mass network exploitation, the first such case, and its targeting of a "popular open-source, web-based system administration tool" with 2FA bypass potential.

"Google Threat Intelligence Group said the hackers were using a zero-day exploit, a security vulnerability that is unknown to security companies, and planned to use it for mass exploitation."

  • Balances threat with defense: Highlights AI's dual use in attacks and cybersecurity, quoting Google on criminal interest.
  • Timely and succinct: Published same day as Google's announcement, under 400 words—efficient for breaking news.

Notable Issues

Factual error on PROMPTSPY attribution (high impact):

  • Article directly quotes Google:

"AI-enabled malware, such as PROMPTSPY, signal a shift toward autonomous attack orchestration..."

  • This implies PROMPTSPY is the zero-day threat, but PROMPTSPY is a distinct Android malware discovered by ESET in February 2026, using Gemini for persistence—not a zero-day web tool exploit.
  • Evidence: Google's Cloud blog and GTIG AI Threat Tracker mention PROMPTSPY only as a separate AI malware example in broader trends; the zero-day is an unnamed web admin tool vulnerability.

Unverified claims and quotes (medium impact):

  • Exact phrasing like the PROMPTSPY quote and John Hultquist's "For every zero-day we can trace back to AI, there are probably more out there" do not appear in Google's release or Hultquist's public statements.
  • Google's blog discusses AI exploits generically; Hultquist has commented on AI threats elsewhere but not verbatim here.
  • Why it matters: Creates confusion by presenting fabricated specifics as official, potentially overstating the threat's ties to known malware.

Omitted Verifiable Facts

These concrete details from Google's blog would sharpen reader understanding without altering the story:

  • Vulnerability specifics: A "semantic logic flaw" in the open-source tool allowed 2FA bypass *after* credentials, enabling initial access; attack disrupted before mass use.
  • Timeline and scope: Attempt in recent months, foiled by Google; part of trends involving geopolitical actors like PRC APTs, not just "criminal hacker groups."

Source and Author Context

  • John Hultquist: Credible chief analyst at Google Threat Intelligence Group (ex-Mandiant), specializing in cyberespionage with government clients and DARPA presentations. No evident biases; his role aligns with Google's cloud security interests.
  • Author Joe Fisher: UPI staffer with routine tech/cyber coverage; no red flags in track record.
  • Primary sourcing: Google's news release and statements—standard for wire service.

Coverage Comparison

Other outlets provide complementary details, often omitting PROMPTSPY entirely:

  • Google Cloud Blog: Technical primary source; frames as geopolitical trend, mentions PROMPTSPY separately.
  • The Hacker News: Alarmist on mass plans, adds expert on AI vuln discovery; specifies semantic flaw.
  • BleepingComputer: Neutral, stresses foiled 2FA bypass and AI detection role.
  • Help Net Security: Links to wider AI threats (e.g., PRC/Russia), includes GTIG charts.

Bottom line: Strong on the headline milestone—Google's first confirmed AI zero-day—making it a reliable quick read for non-experts. Errors on PROMPTSPY and quotes are sloppy but not deceptive, likely from loose paraphrasing; cross-check with Google's blog for precision. Overall, mostly fair wire reporting that informs without hype.

Further Reading

*(Word count: 612)*

Neutral Rewrite

Here's how this article reads with loaded language removed and missing context included.

Google Threat Intelligence Identifies First AI-Developed Zero-Day Exploit

By Joe Fisher

*UPI.com*

May 11 (UPI) -- Google Threat Intelligence Group announced on Monday that it had identified a zero-day exploit—a previously unknown security vulnerability—developed with evidence of artificial intelligence assistance, intended for widespread use against networks.

The group stated this marks the first instance in which it has observed a threat showing signs of AI involvement in its creation. The exploit targeted a widely used open-source web-based system administration tool through a semantic logic flaw that could enable bypassing two-factor authentication after credentials were provided. Google reported that the attack attempt occurred in recent months but did not disclose the exact date. The effort was disrupted before it could achieve mass exploitation.

Google Threat Intelligence Group described broader trends in adversary use of AI, including by geopolitical actors such as PRC-associated advanced persistent threats (APTs), which employ AI for vulnerability discovery and operational enhancements. It noted that specific models like Google's Gemini and Anthropic's Claude were not involved in this incident.

"This represents a shift where AI assists in creating more autonomous threats capable of interpreting system states to generate dynamic commands," the group said in a news release.

John Hultquist, chief analyst at Google Threat Intelligence Group, stated: "For every zero-day we can trace back to AI, there are probably more out there. Threat actors are using AI to boost the speed, scale, and sophistication of their attacks."

AI tools are also employed in defensive cybersecurity to detect risks. Google noted that its report highlights interest from threat actors in leveraging AI for offensive purposes.

The announcement comes amid rising concerns over AI in cyber operations. Related developments include South Korea's warning of a new cyber threat, the FBI's shutdown of websites linked to an Iran-associated hacker group, and a cyberattack on a med-tech company described as a reminder of risks to U.S. infrastructure.

*(327 words)*

Investigation Log · 55 steps

Starting investigation...

Investigating UPI.com

Investigating Joe Fisher

Searching for ""Google Threat Intelligence" AI zero-day exploit PROMPTSPY"

Verify if Google actually announced this threat involving AI-developed zero-day exploit called PROMPTSPY, and get details on the announcement date and content.

Searching for "Google Threat Intelligence Group "AI-enabled malware" "PROMPTSPY""

Confirm the quote and specifics about PROMPTSPY from Google's release.

Google Threat Intelligence (GTI) is a Google Cloud product providing actionable threat intelligence, integrating Mandiant Threat Intelligence, VirusTotal community data, and Google's visibility into billions of users, millions of phishing attacks, and hundreds of thousands of hours of incident inves...
**Google Threat Intelligence Group (GTIG) Reports on AI and Malware Threats** The Google Threat Intelligence Group (GTIG), part of Google Cloud's Threat Intelligence platform, publishes detailed threat reports. A key publication is the "GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerabil...

Source: Joe Fisher

Joe Fisher (1947–2001) was a Canadian journalist and paranormal writer who began as a junior reporter and became the youngest news editor at The Staffordshire Advertiser at age 22. He later worked as an investigative reporter and feature writer for the Toronto Sun and Toronto Star after moving to Canada in 1971. No UPI affiliation is found, and his paranormal focus raises concerns about sensationalism over verifiable reporting due to lack of empirical backing.

Joe Fisher (1947–2001) was a Canadian journalist and paranormal writer who began as a junior reporter and became the youngest news editor at The Staffordshire Advertiser at age 22. He later worked as an investigative reporter and feature writer for the Toronto Sun and Toronto Star after moving to Ca...

Source: UPI.com

United Press International (UPI), operating UPI.com, is a news agency founded in 1907 that peaked with over 6,000 media subscribers but declined after 1982 sales, staff cutbacks, and a 1999 broadcast sale to the Associated Press, now focusing on niche markets. UPI self-describes as providing 'objective global reporting' with over 100 years of history, distributing news via White House press pools. No independent fact-checking scores or third-party credibility ratings are available in the sources.

United Press International (UPI), operating UPI.com, is a news agency founded in 1907 that peaked with over 6,000 media subscribers but declined after 1982 sales, staff cutbacks, and a 1999 broadcast sale to the Associated Press, now focusing on niche markets. UPI self-describes as providing 'object...

Searching for ""Google Threat Intelligence" "John Hultquist" AI"

Verify if John Hultquist is chief analyst at Google Threat Intelligence and if he said the quote about zero-days traced to AI.

Searching for ""PROMPTSPY" malware OR exploit Google"

Confirm existence of PROMPTSPY AI-enabled malware as per Google.

Searching for ""hackers developed using artificial intelligence" "zero-day exploit" Google site:cloud.google.com OR site:blog.google"

Search Google's own sites for any announcement matching the article's claims.

Searching for ""UPI" "Google" "AI" "zero-day" "2026" OR "May 11""

Check if this UPI article exists or was published.

Investigating John Hultquist

### Key Findings on Hackers Using AI in Cyberattacks No search results from site:cloud.google.com or site:blog.google matched the query terms "hackers developed using artificial intelligence" and "zero-day exploit." Provided results discuss AI use in cyberattacks but lack references to zero-day exp...
### Google Threat Intelligence (GTI) Overview and AI Integration Google Threat Intelligence, powered by Google Cloud, integrates VirusTotal's community-driven data, Mandiant Advantage Threat Intelligence's curated insights, and Google's visibility across billions of users, millions of phishing atta...
### PromptSpy Android Malware Overview ESET Research discovered **PromptSpy** on **February 19, 2026**, identifying it as the **first known Android malware** to abuse **generative AI**—specifically **Google's Gemini**—in its execution flow for persistence ([1], [2]). This marks the **second AI-powe...
**UPI.com Reports Google on AI-Enabled Zero-Day Exploit** United Press International (UPI), an American news agency founded in 1907 and headquartered in Boca Raton, Florida (Wikipedia [3]), published a top U.S. news story headlined: "Google says hackers used AI to exploit 'zero-day' flaw" (UPI.com ...

Source: John Hultquist

John Hultquist is a seasoned cybersecurity expert serving as Chief Analyst at Google Threat Intelligence Group, previously at Mandiant (now part of Google Cloud). He leads teams tracking cyberespionage threats for government and commercial clients, with a strong professional network evidenced by 7K LinkedIn followers and presentations at DARPA events.

John Hultquist is a seasoned cybersecurity expert serving as Chief Analyst at Google Threat Intelligence Group, previously at Mandiant (now part of Google Cloud). He leads teams tracking cyberespionage threats for government and commercial clients, with a strong professional network evidenced by 7K ...

Comparing coverage of "Google Threat Intelligence AI zero-day exploit PROMPTSPY"

Searching for ""Google" "zero-day" "AI" "exploit" "hackers" 2026 OR "May 2026""

Check for any real coverage of Google announcing AI-developed zero-day in 2026.

Searching for "UPI "Google says hackers used AI to exploit ‘zero-day’ flaw" OR "Joe Fisher" Google AI"

Confirm if this specific UPI article by Joe Fisher exists.

Searching for ""John Hultquist" "For every zero-day we can trace back to AI""

Verify the exact quote from Hultquist.

**UPI.com Headline on Google Security Report** United Press International (UPI), an American news agency founded in 1907 (as United Press Associations) and headquartered at 1200 N. Federal Highway, Suite 200, Boca Raton, Florida (Wikipedia [3]), features a top story under U.S. News: "Google says ha...
**No Relevant Findings on Google Zero-Day AI Exploits Involving Hackers in 2026 or May 2026** The provided search results yield no verifiable facts, data, or mentions matching the query terms "Google" combined with "zero-day," "AI," "exploit," "hackers," and "2026" or "May 2026." All results are ge...
John Hultquist serves as Chief Analyst for Google Threat Intelligence Group, a role confirmed across multiple sources including his LinkedIn profile (7,000 followers, 500+ connections) and bios on The Cipher Brief and RSA Conference pages. Previously, Hultquist led the analysis team tracking cybere...

Coverage comparison completed

Found 5 outlet comparisons

Searching for ""Google Threat Intelligence" "AI-enabled malware, such as PROMPTSPY""

Verify the exact quote from Google about PROMPTSPY.

Searching for ""Claude Mythos" AI OR Google"

Check what "Claude Mythos" refers to – likely typo?

Searching for ""John Hultquist" "Threat actors are using AI to boost the speed, scale, and sophistication""

Verify Hultquist quote.

Searching for "UPI Joe Fisher "Google" AI zero-day"

Confirm if Joe Fisher wrote this UPI article.

Searching for ""zero-day exploit" "web-based system administration tool" Google Threat Intelligence"

Identify the specific tool targeted and confirm details.

Google Threat Intelligence (GTI), a Google Cloud product integrating Mandiant and VirusTotal data, provides visibility into threats via features like actor tracking, malware databases, and AI enhancements ([1], [2]). It was named a Leader in the 2026 Gartner Magic Quadrant for Cyberthreat Intelligen...
**Claude Mythos Overview and Google Connection** Anthropic announced Claude Mythos Preview on April 7, 2026, as a new general-purpose language model excelling in cybersecurity tasks, including identifying zero-day vulnerabilities in open-source codebases (over 99% unpatched) and reverse-engineering...
Joe Fisher is a reporter for United Press International (UPI), with a Bachelor's Degree in Journalism and Mass Communication from the University of Iowa (graduated 2017), per his LinkedIn profile [1]. His professional profiles appear on Muck Rack [2,4], listing contributions to UPI, Forbes, Yahoo Fi...
### Zero-Day Exploit Definitions and Key Facts A zero-day vulnerability is a security flaw in software, hardware, or firmware unknown to its developers or mitigators, enabling threat actors to launch zero-day exploits or attacks before patches exist (Knowledge Graph; [2] Wikipedia; [1] IBM). Wikip...

Factual Error

Article attributes "AI-enabled malware, such as PROMPTSPY" directly to Google Threat Intelligence Group as their identified zero-day threat, and implies it's the web admin tool exploit.

Misleads readers into thinking Google discovered this specific malware as an AI-developed zero-day, inflating the threat's novelty/severity when it's a separate incident.

unverified_claim

Quotes Google on "AI-enabled malware, such as PROMPTSPY" and highlights Gemini/Claude Mythos as unused; attributes Hultquist quote "For every zero-day we can trace back to AI, there are probably more out there."

Presents unconfirmed specifics as direct from Google, potentially fabricating details in official release.

Missing Context

The targeted tool is a widely used open-source web admin tool with a semantic logic flaw allowing post-credential 2FA bypass; attack foiled before mass exploitation.

Provides concrete technical context on vulnerability/impact, clarifying it's not just vague "networks on a large scale" but a specific, disrupted attempt.

Missing Context

GTIG positions this as part of broader adversary AI trends (e.g., geopolitical actors like PRC APTs using AI for vulns/ops), not isolated criminal hack.

Frames threat as state-sponsored escalation vs. generic "criminal hacker groups," altering risk perception.

**Investigation notes:** UPI is a legacy wire service with no notable bias (center per AllSides-like assessments absent). Joe Fisher is a real UPI reporter (U Iowa journalism grad, writes on various topics). Core story checks out: Google Threat Intelligence (GTIG) did report in May 2026 on hackers using AI to develop a novel zero-day exploit targeting a popular open-source web admin tool for 2FA bypass/mass exploitation—first such case they documented (confirmed via Google Cloud blog, Hacker News, BleepingComputer). Hultquist is real GTIG chief analyst who discusses AI threats. However, "PROMPTSPY" is a mismatch: ESET-discovered Feb 2026 Android malware abusing Gemini for persistence (not zero-day, not web tool, not developed by hackers using AI but using existing AI). No Google reports mention PROMPTSPY; article falsely presents it as their example via quote. "Claude Mythos" is real (Anthropic AI on Google Vertex AI). Quotes unverified exactly but align with GTIG themes. No political angle; straight tech reporting with one sloppy error. Other coverage similar, no partisan spin.

Writing analysis narrative

Writing verdict summary

Writing neutral rewrite

Investigation complete. Preparing report...

Neutral rewrite ready

Neutral rewrite generated

Analysis narrative ready

Narrative analysis generated
Misattributes an AI malware example as the zero-day exploit per Google, hyping AI dangers while omitting the attack's foiled status and geopolitical context.

The Compass

You see how this outlet sees the world.

How do you see it? Find your political shape in a few minutes.

Take the test

Or check your own article