A team of Canadian researchers has just confirmed what cybersecurity experts have been dreading: AI can now be used to build computer worms that think for themselves. And the threat is closer than most people realize.
Researchers at the University of Toronto's CleverHans Lab, led by Associate Professor Nicolas Papernot, published findings in June 2026 showing that freely available AI models - the kind anyone can download - can power a self-spreading worm that adapts its attack strategy with each new device it targets. The research was conducted in a controlled lab environment and shared with national science, security, and defence bodies before going public.
What Makes an AI Worm Different?
Traditional computer worms follow a fixed script. They look for one type of vulnerability, exploit it the same way every time, and security teams can eventually write a patch or filter to stop them.
AI-driven worms don’t work that way.
Instead of a fixed attack path, these worms assess each target individually and choose their approach based on what they find. As they spread from one device to the next – laptops, printers, cameras, servers – they gather information and use it to unlock the next machine. Every breach feeds the next one.
What makes this especially concerning is the cost model. Because the worm runs on stolen computing power from the devices it has already compromised, the cost to the attacker drops to near zero as the infection grows. That changes the economics of a cyberattack in a big way – large-scale attacks that once required significant resources become cheap to launch and hard to stop.
Who's at Risk?
Short answer: everyone with a device connected to the internet.
The U of T team specifically identified these potential targets in their research: laptops, printers, security cameras, and any other internet-connected device. That covers home networks, small businesses, schools, hospitals, and critical infrastructure alike.
The worm they built in the lab was tested against vulnerabilities spanning both well-known security flaws (like SQL injection and default credentials) and newly disclosed ones that post-dated the AI model’s own training data. The fact that it could adapt to attack vulnerabilities it had never specifically “learned” is what makes this class of threat particularly serious for defenders.
What Security Experts Are Saying
Professor Papernot spoke at a University of Toronto panel discussion last week, and his message was direct: basic cybersecurity habits are no longer optional.
“We can no longer be sloppy with our cybersecurity hygiene. We can no longer afford to reuse passwords. We have to use multi-factor authentication. We have to keep our devices up to date – and organizations have to change their processes to make sure that software patches are deployed as quickly as possible.”
His team chose to publish their findings rather than keep them under wraps – a deliberate decision to give defenders a head start before this type of attack is deployed by real-world threat actors.
Where Canadians Stand Right Now
A survey by the Communications Security Establishment (CSE) – Canada’s federal cybersecurity agency – found a mixed picture when it comes to digital habits:
- 87% of respondents said they regularly update software on their devices
- 77% said they use complex passwords with a mix of letters, numbers, and symbols
- Only 31% reported using a unique password for every account
That last number is the problem. Reusing passwords is exactly the kind of weak point an AI worm can exploit – one breached password becomes a key that opens door after door.
5 Steps to Protect Yourself Right Now
You don’t need to be a security expert to reduce your risk significantly. These are the basics that security researchers consistently recommend:
1. Install software updates promptly. Don’t dismiss those update notifications. Patches exist to close the specific vulnerabilities worms look for. Delaying them gives attackers a window.
2. Stop reusing passwords. Use a password manager to generate and store unique, complex passwords for every account. This is one of the single most effective things you can do.
3. Turn on multi-factor authentication (MFA). Even if a password is compromised, MFA adds a second barrier. Enable it on email, banking, social media, and any admin tools you use.
4. Audit your connected devices. Routers, cameras, smart devices, and printers are often overlooked but are exactly the kind of targets AI worms are built to exploit. Change default credentials and make sure firmware is up to date.
5. Don’t ignore unusual device behaviour. Sluggish performance, unexpected data usage, or devices acting on their own can all be signs of compromise. If something feels off, have it checked.
Frequently Asked Questions
An AI computer worm is a type of self-spreading malware that uses artificial intelligence to adapt its attack strategy as it moves from device to device. Unlike traditional worms that follow a fixed script, AI-driven worms assess each new target and choose their approach based on what they find - making them harder to detect and stop.
A regular virus typically relies on a known, predictable attack pattern that security software can learn to recognize and block. An AI worm reasons about each target individually and can exploit vulnerabilities it wasn't specifically programmed for - including newly discovered ones. It also spreads without any human involvement and runs on stolen computing power from infected devices, making each subsequent attack essentially free for the attacker.
Yes. Researchers at the University of Toronto specifically identified home and consumer devices - laptops, printers, and security cameras - as potential targets alongside corporate infrastructure. Any device connected to the internet is considered part of the attack surface.
The fundamentals still go a long way: install software updates as soon as they're available, use a unique password for every account (a password manager makes this easy), enable multi-factor authentication wherever possible, and change default credentials on any connected devices like routers and cameras. These steps close the exact vulnerabilities AI worms are designed to exploit.
The University of Toronto research was conducted in a controlled lab environment as a proof of concept - not an active attack. However, researchers published their findings specifically because similar threats are believed to be in development by real-world threat actors. The goal was to give the cybersecurity community a head start on building defences before these worms appear in the wild.
The Bottom Line
AI is changing cybersecurity – and not just in ways that help defenders. The same publicly available models being used to build productivity tools can be repurposed to build threats that are smarter, faster, and cheaper to deploy than anything we’ve seen before.
The good news is that basic hygiene still goes a long way. Keeping software updated, using strong unique passwords, and enabling MFA aren’t glamorous – but they close the doors that AI worms are specifically designed to walk through.
If you’re managing a business website or online presence and want to make sure your setup is locked down, reach out to the Valiant Digital team. We can take a look at what you’re running and flag anything that needs attention.
Sources: University of Toronto / CleverHans Lab (June 2026 research), CBC News (September 12, 2026), Communications Security Establishment (CSE) survey






