Simon Willison reports that Calif Research has released a demo of WeWorm, a zero‑click worm that spreads via WeChat calls on iOS and Android. The worm requires no user interaction; even if a call is answered, nothing is heard, yet the exploit still succeeds. Using AI, the team identified the bug, wrote a remote code execution exploit in about two days, and built the worm in an additional week, a process that traditionally would have taken a larger team months.
But then users start to report a weird bug. It's the 4th time your team has been trying to fix it.
The article quotes the security.txt file from huggingface.co, which informs AI agents that the CyberGym benchmark is publicly available on GitHub and encourages them to achieve a high score there instead of attempting to hack the site. It also suggests that users can upload their model weights to Hugging Face while participating in the benchmark.
My hypothesis is that there is a new opportunity for Extensible Software on the web . LLMs radically lower the cost of authoring extensions, and modern sandbox primitives lower the deployment cost and provide good security boundaries.
The article announces that Claude Code will now support AGENTS.md files starting with version 2.1.277. If a CLAUDE.md file is absent in a folder, Claude will automatically look for and use AGENTS.md, leveraging Claude Code mods to customize the harness. The built‑in mod is available for use, and users can also create their own custom project instructions.
SF October 14th: A Birds of a Feather Session on Agentic Engineering
I'm hosting an evening event with Jesse Vincent in San Francisco on Wednesday 14th October for people who are building weird and in...