Gadgetreview AI Worms Exploit Vulnerabilities in Devices via Custom Attack Playbooks
Article Content
- •AI worms can autonomously exploit vulnerabilities without an attacker server.
- •The worm compromised 62% of a 33-host network in just seven days.
- •A zero-click attack on WeChat allows account hijacking before calls are answered.
Researchers at the University of Toronto demonstrated a self-replicating AI worm that compromised 62% of a simulated 33-host network within seven days. This worm, powered by a free large language model, autonomously identifies vulnerabilities in devices such as laptops, phones, and IoT systems. It utilizes a zero-click attack method exploiting WeChat's VoIP stack, allowing it to hijack accounts before calls are answered. The worm can generate tailored exploits in real-time, including those for newly disclosed vulnerabilities like the CopyFail Linux kernel bug. The study highlights the adaptability of this malware, which does not rely on fixed scripts and can operate without an attacker-controlled server. The findings raise significant concerns about the security of connected devices and the potential for widespread exploitation. Current defenses against such threats remain inadequate.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track WannaCry, WeWorm and Calif in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…
Unisoc Modem Vulnerability Allows Remote Code Execution via Video Calls Researchers have discovered a critical vulnerability in Unisoc modem firmware that allows attackers to gain root access to various Android devices through a video call exploit. This vulnerability affects multiple budget smartphones powered by Unisoc chipsets, including the Realme C33, Xiaomi Redmi A5, and Motorola…