Quoting Calif Research
- ID
- 23023
- Status
- summarized
- Published
- 10 Sep 2026, 8:56 AM
- Fetched
- 10 Sep 2026, 9:39 AM
- Provider
- Simon Willison
- Category
- developer-ai
- Original URL
- https://simonwillison.net/2026/Sep/10/calif-research/
- Source URL
- https://simonwillison.net/atom/everything/
Summary
- Score
- 7.5
- Created
- 10 Sep 2026, 9:40 AM
- Tags
- Audience
- developersai_ml_learnerssaas_founders
What happened
Calif Research demonstrated WeWorm, a zero-click worm that spreads through WeChat calls on iOS and Android without the victim answering or interacting. Their team used AI to find the bug and write the first RCE exploit in about two days, then built the worm in one more week—work that previously took a larger team months.
Why it matters
This is a concrete data point on how AI compresses offensive security timelines from months to days. If you ship mobile or messaging software, assume that AI-assisted adversaries can find and weaponize vulnerabilities in your stack far faster than before—prioritize faster patch cycles and threat modeling over perimeter defenses.
Discussion angle
What does a 10x reduction in exploit development time mean for your team's patch SLA and bug bounty strategy—and are you still budgeting security effort as if adversaries move at human speed?