News

Researchers Demonstrate AI Worm Capable of Self-Spreading Across Connected Systems

AI Worm Demonstrates New Class of Security Threat

Security researchers have created an AI-powered worm capable of spreading between devices and services without requiring any human interaction. The proof-of-concept malware, dubbed "Morris II" in reference to the infamous 1988 Morris internet worm, successfully exploited vulnerabilities in AI systems including Gmail and ChatGPT.

How It Works

The worm leverages adversarial prompts to bypass AI safety guardrails. When an AI assistant processes a poisoned message containing a self-replicating prompt, it can inadvertently generate and execute malicious instructions that propagate to other connected systems. This allows the worm to spread autonomously through email systems, AI-powered services, and other interconnected platforms.

Capabilities and Implications

Once inside a system, Morris II can perform various malicious activities, including:

  • Extracting sensitive user data from email conversations
  • Injecting spam content into AI-assisted messaging
  • Replicating itself by compromising additional AI agents

Researchers emphasize that traditional cybersecurity approaches offer limited defense against this threat. Unlike conventional malware that targets specific software vulnerabilities, this attack exploits the fundamental architecture of how AI systems process and respond to external inputs.

Industry Response

The demonstration highlights growing concerns about AI system security as these technologies become increasingly interconnected. Security experts warn that as AI agents begin communicating with each other and accessing multiple services, the potential attack surface expands significantly.

The research team has shared their findings with affected companies, though experts note that addressing such vulnerabilities requires fundamental changes to how AI systems handle untrusted inputs rather than simple security patches.

Sources