Skip to content
AI Worms Exploit Vulnerabilities in Devices via Custom Attack Playbooks

AI Worms Exploit Vulnerabilities in Devices via Custom Attack Playbooks

First seen 15 Sep 2026, 05:20 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 05:20 UTC
  • AI worms can autonomously exploit vulnerabilities without an attacker server.
  • The worm compromised 62% of a 33-host network in just seven days.
  • A zero-click attack on WeChat allows account hijacking before calls are answered.

Researchers at the University of Toronto demonstrated a self-replicating AI worm that compromised 62% of a simulated 33-host network within seven days. This worm, powered by a free large language model, autonomously identifies vulnerabilities in devices such as laptops, phones, and IoT systems. It utilizes a zero-click attack method exploiting WeChat's VoIP stack, allowing it to hijack accounts before calls are answered. The worm can generate tailored exploits in real-time, including those for newly disclosed vulnerabilities like the CopyFail Linux kernel bug. The study highlights the adaptability of this malware, which does not rely on fixed scripts and can operate without an attacker-controlled server. The findings raise significant concerns about the security of connected devices and the potential for widespread exploitation. Current defenses against such threats remain inadequate.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-02
AI worm research published
University of Toronto published findings on AI-driven computer worms that adaptively exploit vulnerabilities.
Gadgetreview
2026-09-2026
WeWorm zero-click exploit disclosed
Palo Alto security firm Calif revealed a proof-of-concept worm exploiting WeChat's VoIP stack.
Tech.Yahoo
Recent
Vulnerabilities identified
The AI worm identified an average of 31.3 vulnerabilities per run across various operating systems.
Gadgetreview

More articles in this cluster (3)

Following this threat?

Track WannaCry, WeWorm and Calif in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed