University of Toronto researchers have developed a proof-of-concept agentic AI worm capable of autonomously identifying and exploiting network vulnerabilities to spread across Linux, Windows, and IoT devices.
Key Points
- The AI worm uses open-source large language models to dynamically adapt its attack strategy to the specific vulnerabilities of each targeted device.
- In a simulated corporate environment, the autonomous malware successfully compromised 73.8% of the isolated test network within seven days.
- The worm sustains itself by stealing compute resources from infected machines to host the LLMs, effectively reducing the cost of propagation for attackers.
- Unlike traditional static malware, this agent can ingest real-time public security advisories to exploit vulnerabilities before organizations have the opportunity to apply patches.
- Cybersecurity experts emphasize that the threat relies on existing weaknesses like poor identity controls, misconfigurations, and legacy systems rather than novel AI capabilities.