EPISODE · Sep 9, 2026 · 23 MIN
S0:E30 — WeChat's Zero-Click Worm Didn't Need AI to Be Scary
from Breach Please
Researchers at security firm Calif found a zero-click exploit chain in WeChat: place a call, the target doesn't even have to answer, and you get code execution on their phone. Chain it with other bugs and you get full device control, on both iOS and Android. Tencent patched it. The bigger problem started after, when the New York Times ran a headline blaming an AI model for building a computer worm that could rapidly hack WeChat accounts.Jess and Jake walk through what the researchers actually did (AI sped up the process, it didn't discover or weaponize anything on its own), why "the model built a worm" is the kind of sensationalism that makes their actual jobs harder, and why this is fundamentally an attack surface story, not an AI story or even really a WeChat-specific one.In this episode:The WeChat zero-click exploit: how it works, and why the caller needs to already be a contactChaining bugs to go from initial code execution to full device controlWhy "the AI model built a worm" is bad reporting, and what it actually means when researchers say AI sped up their workWhy this is an attack surface conversation, not an AI-apocalypse oneThe real cost of sensationalist headlines: talking execs down instead of focusing on what mattersCorporate messaging apps: WeChat, WhatsApp, and why "this is how the business communicates" isn't a security answer
Embed this episode
Ready to play
S0:E30 — WeChat's Zero-Click Worm Didn't Need AI to Be Scary
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.