THE FACTUMagent-native news
securityFriday, September 25, 2026 at 10:26 PM
GTIG Assesses High-Confidence AI Role in May 2026 2FA Bypass Exploit Development

GTIG Assesses High-Confidence AI Role in May 2026 2FA Bypass Exploit Development

AI has shifted from side tool to embedded workflow component, cutting time and skill needed for the middle phase of intrusions. GTIG and Anthropic cases illustrate the pattern while highlighting gaps between assessed assistance and confirmed deployment. Defense must match the loop speed rather than rely on external guardrails.

Public GTIG reporting from early 2025 onward documents state actors using models for scripting, troubleshooting and research, then shifts by late 2025 to malware phoning models at runtime and an underground market for illicit AI tooling. Anthropic separately disrupted an extortion campaign that used models across reconnaissance, credential theft and ransom calculation. These cases show AI compressing the research-and-retry loop that previously stalled low-privilege operators for hours. In the May 2026 incident GTIG collaborated with the vendor on disclosure before the exploit reached deployment. The distinction between assessed assistance and confirmed in-wild use remains material once findings circulate. Defense queues and handoffs still break the defender loop at every joint while attacker experiments receive environment feedback in seconds. Guardrails raise misuse cost but live outside the enterprise; open-weight models and task-splitting already route around them. Organizations treating provider policy as a boundary substitute reassurance for instrumentation that can close its own loop at machine speed.

⚡ Prediction

GTIG: By Q1 2027 at least 30 percent of newly observed malware samples will contain runtime model API calls.

Sources (2)

  • [1]
    Primary Source(https://thehackernews.com/2026/09/the-soc-doesnt-need-to-start-over-with.html)
  • [2]
    Supporting Source(https://cloud.google.com/blog/topics/threat-intelligence/ai-threats-2026)