AI · 96 days ago
A worm no longer needs a frontier model or cloud API to spread. A local, open-weight LLM can inspect one machine, spot the next weak link, and keep copying itself across a network using the ordinary gaps defenders already see every day.
University of Toronto researchers showed that with a free model running on local hardware, a prototype worm could self-replicate in a simulated enterprise network by chaining common vulnerabilities and misconfigurations, including reused passwords and newly reported flaws. The same setup also let it use compromised compute on laptops, cameras, servers, and other connected devices to continue the spread.
The forward risk is system-level, not point-fix level. Once one host is in, local inference can keep driving discovery and propagation without any external AI service to block prompts or cut off the attack.
3 sources covering this story
Smashing Security podcast #471: This AI worm just rewrote its own rules
Researchers at the University of Toronto have built a worm that thinks for itself.
Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models
An AI-driven worm using a local open-weight LLM autonomously exploited and replicated across 62% of a 33-host test network in 7 days.
AI worm prototype shows attackers don’t need Mythos to take over your network
University of Toronto researchers demonstrate how open-weight local LLMs can be used to autonomously exploit flaws and misconfigurations typical found in most enterprise networks, feeding off abused GPUs to fuel self-replication.
Part of the PlainSec briefing for 2026-06-10