Find notable cyber news and cases, enriched with sources, timelines, and signals.

AI-driven worm reasons at runtime and self-replicates across a 33-host test network

Technical Analysis
First reported
Last updated
Happening score
H score 40
1 unique sources, 1 articles

Summary

Hide ▲

Researchers demonstrated a proof-of-concept AI-driven worm that reasons at runtime and self-replicates, showing adaptive host-to-host spread across a 33-host vulnerable test network. The prototype raises the risk of runtime exploit generation, fresh-advisory weaponization, and GPU-assisted propagation without a fixed exploit chain.

Related Happenings

HalluSquatting indirect prompt-injection attack on AI coding assistants

Technical Analysis
H score3 First: 08.07.2026 18:07 Last: 08.07.2026 18:07 Sources 1

About this happening: Researchers demonstrated HalluSquatting, an indirect prompt-injection technique that can push AI coding assistants to fetch attacker-controlled resources and execute code....

Sentry agentjacking analysis shows malicious error events can trigger AI coding agents

Technical Analysis
H score38 First: 11.06.2026 12:15 Last: 11.06.2026 12:15 Sources 1

About this happening: Researchers described Agentjacking as a new attack against AI coding agents that abuses Sentry DSNs and MCP to inject fake error data, causing agents like Claude...

Google GTIG analysis of adversary AI use for exploit development and attack orchestration

Technical Analysis
H score33 First: 11.05.2026 16:00 Last: 11.05.2026 16:00 Sources 1

About this happening: Google Threat Intelligence Group published findings showing adversaries using AI for exploit development and attack orchestration, signaling that model-assisted tr...

Langflow CVE-2026-33017 exploitation wave

Exploitation Wave
H score50 First: 20.03.2026 12:20 Last: 20.03.2026 12:20 Sources 1

About this happening: CVE-2026-33017 in Langflow was disclosed on March 17, 2026 as an unauthenticated RCE with CVSS 9.3, allowing arbitrary Python execution from a single HTTP requ...

Underground AI services emerge with jailbroken APIs and MCP servers

Threat Actor Meta
H score11 First: 12.02.2026 14:45 Last: 12.02.2026 14:45 Sources 1

About this happening: Underground AI services are emerging on marketplaces with a model that hides jailbroken commercial APIs and open-source MCP servers, expanding access to malware*...

Timeline

  1. 09.06.2026 14:59 2 articles · 1mo ago

    Researchers demonstrate a self-replicating AI worm on a 33-host test network

    Initial Disclosure

    University of Toronto researchers built and tested a proof-of-concept AI-driven worm that used a locally hosted open-weight LLM to inspect exposed services, read fresh advisories, generate tailored attack logic, and self-replicate across an isolated 33-host FakeCorp network. The prototype found an average of 31.3 vulnerabilities, gained elevated access on 23.1 hosts, replicated to 20.4 hosts over seven days, and rewrote its own code to bypass local security controls; the team also showed runtime exploitation of CVE-2026-39987, CVE-2026-31431, CVE-2026-43284, and CVE-2026-43500 after the model's training cutoff.

    Show sources