#WeWorm
Reserve your slot now at WeWorm
July 1, 2025 at 12:30 AM
Calif developed a zero-click worm that spread through WeChat calls across iOS and Android

blog.calif.io/p/weworm
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
blog.calif.io
September 8, 2026 at 11:19 AM
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io/research/wew...
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io
September 8, 2026 at 6:09 PM
Here's the referenced company material. calif.io/research/wew...
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io
September 8, 2026 at 10:34 AM
"Calif said the attack, which it named WeWorm, was the first known computer worm—a type of malicious software that can leap from machine to machine on its own absent human help
—that could spread across Apple’s iOS and Google’s Android operating systems without needing a victim to click or tap..."
A.I. Models Built a Computer Worm That Could Rapidly Hack WeChat Accounts
The attack, discovered by A.I. researchers, could have compromised hundreds of millions of devices within hours, experts said.
www.nytimes.com
September 8, 2026 at 10:28 AM
WeWorm: Zero-Click WeChat Worm | Discussion
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io
September 12, 2026 at 7:00 AM
WeWorm - The first zero-click worm to spread through WeChat calls across iOS and Android.
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io
September 8, 2026 at 7:58 PM
Das „KI-Update“ liefert dreimal pro Woche eine Zusammenfassung der wichtigsten KI-Entwicklungen. #KI update
KI-Update kompakt: Schöne Neue KI-Welt, WeWorm, KI-Agenten, Tiersprache
Das „KI-Update“ liefert dreimal pro Woche eine Zusammenfassung der wichtigsten KI-Entwicklungen.
www.heise.de
September 9, 2026 at 1:03 PM
lovely. we summoned WeWorms
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io
September 9, 2026 at 3:47 AM
Eine KI hat eine Schwachstelle in WeChat gefunden, über die man in kürzester Zeit eine Milliarde Konten hätte übernehmen können. Sie ist bereits geschlossen. #Security
„WeWorm“: Zero-Click-Wurm hätte alle Konten von WeChat übernehmen können
Eine KI hat eine Schwachstelle in WeChat gefunden, über die man in kürzester Zeit eine Milliarde Konten hätte übernehmen können. Sie ist bereits geschlossen.
www.heise.de
September 8, 2026 at 12:31 PM
The first zero-click worm to spread through WeChat calls across iOS and Android.
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io
September 8, 2026 at 8:21 PM
The NYT lead on this story was AI fears, but the writeup from Calif is worth reading.

AI assisted security research found a severe, 0-click wormable exploit in WeChat, reported it, and it was fixed before it was used to harm people.

Tools that help us find exploits are good, actually.
Zero-Click Worm Spreads Through WeChat Calls on iOS and Android | Thai Duong posted on the topic | LinkedIn
Today we published WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. All it takes is one phone call. You don't have to answer. Within seconds, your WeChat accou...
www.linkedin.com
September 11, 2026 at 4:36 AM
WeChat hier ja nicht so verbreitet. Aber: malware, die sich auf iOS und Android nur durch einen Anruf verbreitet
😳
calif.io/research/wew...
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io
September 8, 2026 at 5:40 PM
WeChat zero-click attack and AI-driven vulnerability discovery

I have for you this morning the disclosure of WeWorm, the zero-click attack against WeChat that reportedly used AI-assisted vulnerability discovery to move from vulnerability to working remote code execution in roughly two days....
WeChat zero-click attack and AI-driven vulnerability discovery
I have for you this morning the disclosure of WeWorm, the zero-click attack against WeChat that reportedly used AI-assisted vulnerability discovery to move from vulnerability to working remote code execution in roughly two days. A pretty scary thought if I may say so. Ted Miracco, CEO of Approov: “The most interesting part of the WeChat exploit isn't the bug; rather, it's the timeline.
itnerd.blog
September 11, 2026 at 12:05 PM
Nope. They are real severe and critical vulnerabilities in open source software.

Here's a great writeup from a security company that used AI to find a wormable condition in WeChat, reported it, and got it fixed:

www.linkedin.com/posts/thaidn...

Where is the 'gaming the system' here?
Zero-Click Worm Spreads Through WeChat Calls on iOS and Android | Thai Duong posted on the topic | LinkedIn
Today we published WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. All it takes is one phone call. You don't have to answer. Within seconds, your WeChat accou...
www.linkedin.com
September 12, 2026 at 12:38 AM
*burp* Calif just demoed WeWorm—zero-click WeChat call worm across iOS and Android. Ring once, hijack the account, call the next friend. AI found the VoIP bug in about two days; Tencent patched Aug 21. Congrats Earth: your social graph is a worm highway. day259.049
September 16, 2026 at 3:59 AM
WeWorm (Calif, 8-sep): gusano de cero clics que se propaga por llamadas de WeChat en iPhone y Android, sin que contestes. Con IA encontraron el fallo y escribieron el ataque en unos dos días. Ya está mitigado. Tu app de mensajes sin actualizar es la puerta más barata: actualízala hoy.
September 16, 2026 at 3:00 AM
WeWorm

The first zero-click worm to spread through WeChat calls across iOS and Android.

calif.io/research/wew...
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
calif.io
September 13, 2026 at 7:49 PM
Still WeChatting anyone?

AI-built worm could have hijacked over a billion WeChat accounts with a single call
The worm could hijack accounts and spread to contacts with a single unanswered call, potentially reaching hundreds of millions of devices within hours
qz.com/calif-wechat...
Calif security firm built AI-powered WeChat worm WeWorm
The worm could hijack accounts and spread to contacts with a single unanswered call, potentially reaching hundreds of millions of devices within hours
qz.com
September 16, 2026 at 5:00 AM
WeWorm: Zero-Click WeChat Worm

https://calif.io/research/weworm
September 12, 2026 at 7:00 AM
专家表示,WeWorm和Anthropic关于其模型被滥用的报告进一步证明,世界上最大的两个人工智能大国需要找到一种方式来共享有关恶意行为者的信息,或澄清各自的意图。

与此同时,任何一国政府都不太可能同意任何限制其自身人工智能能力发展的条款。
“一种新的核武器”:微信蠕虫事件敲响中国AI安全警钟
微信蠕虫攻击事件凸显了人工智能黑客可能带来的破坏力,也让中国意识到其数字基础设施的脆弱性。这可能会让人工智能安全问题成为“习特会”的重要议题。
cn.nytimes.com
September 15, 2026 at 4:11 PM
专家表示,至少建立一条危机时的沟通渠道是有价值的。

“那肯定会是一个alarm,可能是一个警醒吧,”复旦大学副教授江天骄在提到WeWorm时说。

“大家需要坐下来讨论,人工智能是怎样带来和传统问题截然不同的安全和安保风险,以及我们是否需要新的合作框架,”他说。
“一种新的核武器”:微信蠕虫事件敲响中国AI安全警钟
微信蠕虫攻击事件凸显了人工智能黑客可能带来的破坏力,也让中国意识到其数字基础设施的脆弱性。这可能会让人工智能安全问题成为“习特会”的重要议题。
cn.nytimes.com
September 15, 2026 at 4:31 PM