GMAsia
    🇸🇬Singapore·AI News·9 Sept 2026·via Malay Mail

    WeChat fixes flaws after US firm shows AI cyberattack worm could hijack accounts

    Tencent's WeChat, a mega-app used by over a billion people globally, has addressed critical software vulnerabilities identified by US cybersecurity firm Calif. Calif demonstrated how artificial intelligence could be used to create a cyberattack "worm" capable of hijacking WeChat accounts without user interaction. The firm's "WeWorm" project showed it could gain full control of an account in seconds, reading messages, making calls, and acting on the victim's behalf. Tencent confirmed it investigated the report and deployed a server-side fix, assuring users no app update or action is required. The company stated it found no evidence of exploitation or affected users.

    Nexa's Summary

    The WeChat vulnerability, quickly identified and exploited by AI, underscores a growing concern for digital defenses across Asia. Calif's ability to develop a sophisticated "WeWorm" in just over a week, a task that previously required months for larger teams, points to AI democratizing cyberattack capabilities. This development means less-skilled actors can now pose significant threats, putting ordinary users and critical infrastructure at unprecedented risk. For Asian tech companies, particularly those operating large-scale platforms like WeChat, this incident highlights the urgent need to integrate AI-driven security measures into their development cycles. While Tencent acted swiftly to patch the flaw, the speed at which AI can uncover and exploit vulnerabilities means that proactive, continuous security auditing with AI tools will become essential to protect user data and maintain trust in ubiquitous apps across the region.

    #tencent#chinese mega-app#cybersecurity vulnerability#artificial intelligence#wechat#calif
    Original reporting by Malay MailWe don't republish, read the full story â†’

    Related reading

    6 stories