At Black Hat, Google warned of AI-powered attackers. Google's own tracker counts the breakthroughs: zero.
The 'new entry path' on stage is stolen session cookies, a technique older than the models. The genuinely new thing is one AI-built zero-day, and Google caught it before anyone got hit.
"Threat groups are using AI models to develop new exploits and gain entry into corporate networks through new techniques, dragging defenders into an AI-based arms race" [SOURCE ↗]
THE MOVE: ZERO UNDERNEATH, the headline number has nothing behind it
THE CLAIM. at a Black Hat media briefing, Google Threat Intelligence Group and Accenture said threat actors are using frontier and open-weight AI models to develop new exploits and new entry paths into corporate networks.
THE CHECK. Google's own written AI Threat Tracker says it 'has not yet observed' actors achieving breakthrough capabilities that alter the threat landscape. The headline 'new technique' is stealing tokens, cookies and session IDs, which infostealers did long before AI. The one confirmed AI-built zero-day was disclosed May 11 and closed before it was used.
On August 12 at Black Hat USA in Las Vegas, Ryan Whelan of Accenture and John Hultquist of Google Threat Intelligence Group gave a media briefing on AI-enabled attackers. The message, as reported by Cybersecurity Dive: threat actors are using frontier and open-weight models to 'develop new exploits,
🔒 THE FULL AUTOPSY · FREE WITH AN ACCOUNTYou just read the free check. Sign in free, a code by email, no passwords, and the rest unlocks: the evidence trail, the steelman and the rebuttal, all 5 sources with quotes and screenshots, and our on-record call.
Couldn't verify your access. This looks like our error, not yours.