The First AI Worm, "Morris II," and the Prompt Injection Problem
Researchers have built the first AI worm that can hijack email assistants just by being read — bad news for anyone trusting AI to handle their inbox.
- A worm called "Morris II" hides instructions inside plain text; an AI assistant that reads it can leak passwords or credit card numbers and pass the infection to your contacts.
- No clicking or downloading needed — it fooled ChatGPT, Gemini, and an open model in lab tests, and none could even detect it.
- The flaw isn't a bug you can patch: AI reads everything the same way, so it can't tell a real command from a planted one buried in an email or image.
- It spreads almost for free, jumping between assistants and running on the victims' own accounts and computing power.
- Proposed fixes — splitting reading from acting, or adding a screening AI — all slow things down or share the same blind spot, so companies keep shipping features first.
Outlook: Morris II stays in the lab for now, but as businesses hand more decisions to AI agents, this kind of attack looks hard to stop.