The Information Machine
Following·New·first covered 9 Sep 2026·2 sources

Calif Research demos WeWorm, a zero-click WeChat worm built with AI assistance

The gist

Calif Research said a worm of this scale previously required a larger team and months of work, and that AI now handles most of the technical work, suggesting offensive security development timelines have compressed sharply. The case also illustrates how cross-border cybersecurity coordination can fall to private companies when government-to-government channels are restricted.

The full picture

Calif Research published a demo of WeWorm, a zero-click worm that spreads through WeChat calls on iOS and Android without any user interaction. The victim does not need to answer or touch their phone; even if they answer, they hear nothing and the exploit still succeeds. Calif Research said the team used AI to find the underlying bug and write the first remote code execution exploit in about two days, with the full worm taking one additional week to build. Tencent fixed the vulnerability after Calif alerted the company, a coordination that took place despite the Pentagon's ban on working with Tencent due to alleged Chinese military ties.

How it developed
10 September 2026

Calif Research demo of WeWorm published, detailing zero-click spread mechanism through WeChat calls and AI-assisted development timeline of roughly nine days

9 September 2026

Report published describing Calif's discovery of a WeChat worm, the private-sector coordination required to fix it, and governance implications for cross-border AI and cyber threats

Sources
Semafor Technology
The daily email

Want this in your inbox?

I send one email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free