University of Toronto Researchers Develop AI-Driven Worm Exploiting Known Vulnerabilities
Researchers from the University of Toronto have developed a computer worm using a publicly available open-weight AI model. This worm, unlike previous high-profile malware like WannaCry and NotPetya, does not exploit zero-day vulnerabilities but instead targets known, unpatched bugs and misconfigurations. The worm was tested in a controlled environment, spreading through an enterprise test network by identifying and exploiting these vulnerabilities. The researchers intentionally omitted concealment capabilities in the worm to limit misuse and did not release the code publicly. The worm demonstrated the ability to autonomously adapt and exploit vulnerabilities, even those disclosed after the model's training cutoff, by using publicly available security advisories.