A quote from Calif Research
Simon Willison’s Weblog
Subscribe
10th September 2026
Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...]
The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...]
Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week.
A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely.
— Calif Research, WeWorm
Recent articles
The Pelican comparison grid for Astra is pretty interesting - 4th September 2026
OpenAI's rogue agents were caught communicating via public wikis - 4th September 2026
Claude's new system prompt really doesn't want to reproduce song lyrics - 2nd September 2026
This is a quotation collected by Simon Willison, posted on 10th September 2026.
security 629
ai 2,225
generative-ai 1,971
llms 1,937
ai-security-research 40
Disclosures
Colophon
©
2002
2003
2004
2005
2006
2007
2008
2009
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
2020
2021
2022
2023
2024
2025
2026