10 Sources
[1]
Scientists just built a powerful AI computer worm that learns as it spreads
I agree my information will be processed in accordance with the Scientific American and Springer Nature Limited Privacy Policy. We leverage third party services to both verify and deliver email. By providing your email address, you also consent to having the email address shared with third parties
[2]
Autonomous Malware Is No Longer Theoretical: AI Worm Proof Of Concept Created In A Lab
On June 2, 2026, security researchers published a paper about the creation of an AI work. The headline is as subtle as a fire alarm: this lab experiment of a worm is no longer just code that blindly crawls across your environment; it leverages AI models and can now reason, execute, and learn in
[3]
This AI-Driven Computer Worm Can Adapt to Attack Different Devices
What happens when you use AI to create a self-replicating computer worm? A group of researchers did just that, developing a prototype AI-driven worm that could adapt and infect a network of Windows- and Linux-based servers, workstations, and other IoT devices. The disturbing research comes from a
[4]
Researchers show how AI-powered worms could wreak havoc on the internet - Engadget
The new threat can tailor its attack and learn new strategies with each machine infected. We've seen how AI can be used to find flaws in apps and websites, but researchers have now demonstrated how it could be weaponized to exploit those vulnerabilities. A team from the University of Toronto used
[5]
Scientists Find Way to Supercharge Dangerous Computer 'Worms' With A.I.
Cade Metz has reported on artificial intelligence for more than 15 years. Researchers at the University of Toronto say they have found a way to use artificial intelligence to create a dangerous computer "worm" capable of targeting any known flaw in the world's computers and quickly spreading
[6]
'A Fundamentally New Threat': Researchers Develop New AI-Powered Worm That Might Be Unstoppable
It's a nightmare scenario that's long haunted the imaginations of cybersecurity experts: computer malware that spreads autonomously from device to device, learning as it goes and exploiting different vulnerabilities along the way. Now, researchers have demonstrated that such a "worm" can in fact be
[7]
A new AI-powered computer worm could prove to be the stuff of cybersecurity nightmares | Fortune
In cybersecurity, few words trigger more dread than 'wormable' -- a vulnerability that could be weaponized into a self-spreading worm. Now researchers at the University of Toronto have demonstrated something worse: an AI-driven worm that can't be stopped by patching a single flaw, because it uses
[8]
Researchers create AI worm that adapts attacks without human input
Researchers at the University of Toronto have developed a prototype AI-powered worm capable of exploiting known computer vulnerabilities, potentially posing new threats to internet security. This worm autonomously tailors its attack strategies as it infects machines and does not require human
[9]
This new AI-powered worm spreads itself and adapts in real time -- here's how to stop it
Sara Heritage is a tech and gaming journalist, who's currently making her way up to Master Ball rank in Pokemon Champions. Bylines in IGN, GAMINGbible, The Gamer and more. You can usually find her tinkering with tech, or restoring old consoles, always with one of her 3 cats nearby. Come and talk
[10]
Major Data Breach: Self-Replicating AI Worm Infects 75% of Devices in 7 Days
Researchers have demonstrated a new AI-powered worm that can move from one computer to another on its own. The finding has sparked concern about how future cyberattacks may become harder to stop. Researchers at the University of Toronto have discovered an AI-powered worm that can spread across
Share
Copy Link
Researchers at the University of Toronto have created a prototype AI computer worm that spreads autonomously across networks, learning and adapting its attacks with each infection. Built using freely available open-weight AI models, the worm infected half a test network in five days, exploiting known vulnerabilities across Windows, Linux, and IoT devices. Experts call it a wake-up call for cybersecurity preparedness.
Researchers at the University of Toronto have demonstrated that autonomous malware powered by artificial intelligence is no longer theoretical. The team created a prototype AI computer worm capable of spreading across networks without human intervention, adapting its attack strategies as it encounters different systems
1
. The findings, published in a preprint paper on arXiv, represent what experts describe as a wake-up call for the cybersecurity community1
.
Source: Fortune
Unlike traditional worms that exploit specific vulnerabilities and can be stopped by patching those flaws, this AI-driven computer worm uses a recursive reasoning loop to detect and exploit diverse vulnerabilities as it propagates
3
. The research team, led by Nicolas Papernot, an associate professor in the Department of Electrical and Computer Engineering and Computer Science, conducted 15 independent experiments on an isolated 33-host network spanning Linux servers2
.The researchers built their proof-of-concept using publicly available open-weight AI models that anyone can download from the internet, rather than proprietary systems from companies like Anthropic or OpenAI
1
. The AI-powered computer worm runs on a single Nvidia enterprise GPU, such as the A100 or RTX PRO 6000, which cost between $10,000 and $17,0003
.
Source: Engadget
When the worm gains control of a GPU-equipped host, it deploys a local copy of the large language model, creating an independent reasoning node that serves downstream worm copies on devices without reasoning capability
3
. Each compromised machine becomes part of its infrastructure, providing reach for further attacks or computing resources3
. This means hackers can now prioritize multiple targets simultaneously, as the cost drops to nearly zero once the worm launches4
.The prototype worm spread across a realistic network targeting Windows Server, various Linux distributions, and IoT devices
3
. In the experiments, the worm reached half the network in approximately five days, with an aggregate success exploit rate of 73.8%2
3
. Each experimental run took about seven days to complete, totaling 2,520 hours across all 15 independent runs2
.David Lie, a professor at the University of Toronto familiar with the research, emphasizes that AI-enabled threat operations are especially dangerous because they don't attack a single weakness. Pre-AI worms could only follow certain instructions from their designer, but because this is AI powered, it can learn
1
. The worm gathers data as it moves through networked systems, siphoning passwords and uncovering more vulnerabilities that help it take over other machines4
.The autonomous malware requires hundreds of LLM inference calls for reconnaissance, strategy formulation, and payload generation
3
. While this affords defenders a longer window for detection and response compared to traditional worms like WannaCry, which spread globally within hours in 2017, this window will compress as inference hardware and model efficiency improve3
.
Source: Scientific American
The simulated victim servers and computers were configured with one or more intentionally planted vulnerabilities disclosed months or years earlier
3
. The success rates for exploiting CVEs and CWEs were 52% and 55% respectively, demonstrating that small open-source models are capable, though exploitation remains tricky even with AI2
.Related Stories
The researchers intentionally avoided turning their prototype into operationally deployable malware, refraining from adding evasive capabilities such as encryption, polymorphic code, persistence, forensic cleanup, stealthy traffic shaping, or log suppression
2
. The team withheld certain details, including the specific AI model used, to prevent bad actors from replicating their work3
. They consulted with national security and defense bodies on how to properly disclose their findings3
.The research was conducted in an isolated virtual environment disconnected from the internet
1
2
. Lie notes that this technology is dual use—while AI might enable a worm to learn as it spreads, finding and attacking hidden vulnerabilities, AI can also help fix these shortcomings. "They're mirrors of each other," he says1
.The findings raise serious concerns about AI-powered cyberattacks on critical infrastructure. With almost every aspect of modern life dependent on networked systems—drinking water and waste management systems, access to food and goods, energy, financial systems, communications, health care, education, transportation, and government—the risk is enormous
1
.Papernot emphasizes that you have to have a perfectly secure system to defend against this, and we know that is not currently feasible
5
. As PC and smartphone manufacturers release more devices that can run AI models locally, the threat of AI-driven computer worms could easily grow, giving them a larger pool of devices to exploit3
.Security teams must prepare for handling autonomous threat operations by developing countermeasures as fast as possible
1
. The demonstration shows there's motivation to do this sooner rather than later, as understanding the risks positions the security community to develop the detection and defense capabilities needed against threats like this1
3
.Summarized by
Navi
[1]
19 May 2026•Technology

Yesterday•Technology

01 Jul 2026•Technology

1
Science and Research

2
Technology

3
Policy and Regulation
