行业精选73°

Calif Research发布首个微信零点击蠕虫

Quoting Calif Research

精选理由

Calif Research用AI两天发现微信漏洞,一周开发出零点击蠕虫,比传统方法快得多。

Calif Research团队开发出WeWorm,首个可通过微信通话在iOS和Android设备间传播的零点击蠕虫。受害者无需接听电话或进行任何交互,即使接听也听不到声音,漏洞利用仍会成功。团队利用AI在两天内发现漏洞并编写远程代码执行(RCE)漏洞利用程序,构建蠕虫又用了一周时间。

原文 · Simon Willison’s Weblog

Quoting Calif Research

Today, we're releasing a demo of WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. [...] The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds. [...] Working with AI, our team found the bug and wrote the first remote code execution (RCE) exploit in about two days. Building the worm took one more week. A worm at this scale used to be the kind of thing that took a larger team months. AI can already do most of the work here. Our team provided the judgment about what to target and how to test it safely. — Calif Research , WeWorm Tags: ai-security-research , ai , llms , security , generative-ai