DNYUZ
No Result
View All Result
DNYUZ
No Result
View All Result
DNYUZ
Home News

A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts

September 8, 2026
in News
A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts

A friend you haven’t heard from in a while suddenly calls. You don’t pick up, but in a matter of seconds, the damage is already done.

The call wasn’t actually from an old companion looking to reconnect, but from a hacker who had hijacked that number. Worse, the assailant now secretly has control over your account, including access to your private messages, and is already using your number to reach your saved contacts and compromise them, too.

Like a raging, highly contagious virus, the attack keeps spreading. Within hours, millions of people have suffered the same fate.

A year ago, such a cyberattack might have sounded far-fetched to even the most paranoid digital experts, or at least like something only the world’s most elite spy agencies could have pulled off.

Instead, because of advanced artificial intelligence models, a small team of researchers at Calif, a security company based in Palo Alto, Calif., recently built a hacking tool in a little more than a week that could run roughshod across WeChat, the social media and messaging platform ubiquitous in China.

“This bug is exceptional,” said Thai Duong, the chief executive of Calif, which says it builds hacking tools not to sell them but to bolster cyberdefense. The bug’s simplicity and powerful abilities, he added, would be “a dream come true” for hackers.

The attack is the latest — and one of the most alarming — demonstrations yet of the breakneck speed at which A.I. is progressing, outpacing the ability of regulators and even of leading developers to keep up.

Calif said the attack, which it named WeWorm, was the first known computer worm — a type of malicious software that can leap from machine to machine on its own absent human help — that could spread across Apple’s iOS and Google’s Android operating systems without needing a victim to click or tap on anything. So-called zero-click attacks are different, and far more lethal, than standard phishing emails and texts. They are considered especially pernicious because they are so hard to defend against, given that they do not require a victim to step into a digital booby trap.

A spokeswoman for Tencent, the Chinese technology company that owns WeChat, confirmed the vulnerability and said that it had fixed the issue after being contacted by Calif.

The company had no reason to believe the issue compromised security or affected any users, the spokeswoman said in a statement, adding that no app updates were required by customers.

The discovery is still likely to fuel more concerns that advanced A.I. models could soon usher in a dystopian future that shatters core assumptions about digital security and, at least in the short term, delivers a major advantage to malicious hackers. Calif said it relied on a combination of open-source A.I. models and leading models from the United States, but it declined to specify which ones.

In recent weeks, OpenAI and more than 100 major technology companies, including Calif, warned in an open letter that a wave of A.I.-enabled cyberattacks was coming, and that organizations and governments needed to prepare. The letter followed a spate of cyberattacks from A.I. models, with the models in some cases breaking out of testing environments and attacking other companies. Bill Gates, the billionaire co-founder of Microsoft, said in an interview with The New York Times that addressing these risks should be “the world’s top priority.”

“We have a big challenge in front of us,” Sam Altman, the chief executive of OpenAI, said last week at a Group of 20 nations meeting in North Carolina. “Some things are going to go very wrong with cybersecurity unless some people act quite urgently.”

In the WeWorm attack, once a WeChat account was compromised, a hacker could have read and sent messages, made calls and controlled the victim’s account. Computer worms leverage software vulnerabilities that do not require clicking on a link or a file to automatically deploy their code across a network or the internet, allowing them to spread quickly and easily — in this case, across WeChat accounts. Combined with other security bugs, an attacker could have used the access to a WeChat account to fully compromise a victim’s phone, Calif said.

WeChat has over 1.4 billion active users each month, the company said in a blog post this year, making it one of the world’s most widely used apps. Nearly all of its users are based in China. President Trump is scheduled to host the Chinese leader Xi Jinping this month, and the two men are expected to discuss A.I.

Calif briefed White House officials before publicly disclosing the vulnerability. When asked about the attack, a White House official acknowledged the briefing, noting that A.I. was paving the way for quicker, more advanced attacks and drastically empowering cyber defenders.

In a short research summary published on Tuesday that was reviewed by The Times, Calif said the attack took advantage of how WeChat trusts numbers saved as friends by an account, allowing compromises to spread rapidly from phone to phone. It works if a targeted WeChat user picks up the call or lets it ring, said Mr. Duong, Calif’s chief executive. Only declining the call seconds after a phone’s first buzz would prevent infiltration.

“WeChat, like many messaging apps, gives trusted contacts more privileges,” the summary said. “But once one contact is compromised, that trust works against you.”

Vinh Nguyen, a former chief data scientist at the National Security Agency who reviewed Calif’s research before its publication, said the WeChat worm was one of the most troubling and potentially severe cyberattacks he had ever seen. While self-propagating computer worms have been unleashed before, they were more common decades ago and did not involve mobile software.

The WeChat worm was especially concerning because of its ability to rapidly compromise accounts and then automatically spread to all numbers saved in an account’s address book, allowing it to “propagate exponentially,” said Mr. Nguyen, who is now a senior fellow on A.I. at the Council on Foreign Relations. “Within hours, you could reach hundreds of millions of devices.”

Mr. Duong and his colleague Bruce Dang visited the Palo Alto offices of Tencent, hoping to speak to representatives about a problem they believed was dire. They were unable to find anyone there, however, and departed after taking a photo in front of a Tencent sign.

Flaws like the one Calif identified are known as zero-day vulnerabilities — security holes that are unknown to software makers. They were once considered so rare and powerful that they could fetch millions of dollars on black markets used to sell hacking tools.

But new A.I. models appear to be able to find and weaponize zero-day bugs and other coding flaws that dwarf what security researchers and spy agencies, including the N.S.A., had believed were possible.

When Anthropic’s new Mythos model was announced in April, the company said it had identified thousands of zero-day vulnerabilities “in every major operating system and every major web browser,” including many that were decades old. The dynamic has led Anthropic and other A.I. labs like OpenAI to initially limit the release of their newest, most powerful models to certain companies and government agencies. Doing so, they have argued, can allow major companies to patch critical software weaknesses.

The WeChat attack is just the latest finding from Calif to raise eyebrows. In May, the company disclosed to The Wall Street Journal that it had used an early version of the Mythos model to bypass security protocols in Apple’s macOS operating system, long viewed as highly secure and difficult to breach. Since Mythos and other powerful cyber-focused models built by competing A.I. labs were released to select organizations beginning in the spring, technology vendors have been reporting vastly more high-severity bugs than normal.

In the Apple and WeChat cases, the A.I. systems did not build attacks on their own but relied on mixing their talents with human cybersecurity expertise to discover and leverage them.

“These skills came from years of manual work,” Mr. Duong said, adding, “To exploit it and build a worm, we also need to babysit the entire process.”

The post A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts appeared first on New York Times.

We’ve Forgotten the Most Important Lessons of 9/11
News

We’ve Forgotten the Most Important Lessons of 9/11

by New York Times
September 8, 2026

On Feb. 26, 1993, eight years before 9/11, Islamist terrorists drove a bomb-laden van into the garage of the World ...

Read more
News

California’s later school start times boost grades and mental health, study shows

September 8, 2026
News

A Place Where Memories of the 9/11 Victims Have Faded Away

September 8, 2026
News

I grew my salary to $112K after a career pivot. A layoff broke my heart and changed my perception of money and success.

September 8, 2026
News

Lil Durk’s Murder-for-Hire Trial: What to Know

September 8, 2026
‘Straight to jail’: Explosive report on Trump DHS aide’s dealings reverberates

‘Straight to jail’: Explosive report on Trump DHS aide’s dealings reverberates

September 8, 2026
How NASA Testing Changed US Food Inspection Forever

How NASA Testing Changed US Food Inspection Forever

September 8, 2026
Top Mathematician Announces New Institute for A.I. Safety

Top Mathematician Announces New Institute for A.I. Safety

September 8, 2026

DNYUZ © 2026

No Result
View All Result

DNYUZ © 2026