University of Toronto Researchers Demonstrate AI-Driven Computer Worm Using Open Source Models
Researchers from the University of Toronto have developed a computer worm using a publicly available open-weight AI model, demonstrating its ability to spread through an enterprise test network. The worm autonomously identifies known vulnerabilities and misconfigurations, executing attacks to move laterally and compromise additional systems. This research highlights the potential for attackers to use free, open-source AI models to operationalize known vulnerabilities at scale, posing a significant security threat. The worm was tested in a controlled environment, exploiting publicly disclosed but unpatched vulnerabilities, and demonstrated the ability to adapt and propagate without relying on zero-day exploits.