Researchers from Cornell University [2] [3] [5], Technion-Israel Institute of Technology [2] [3] [5] [8], and Intuit have developed the Morris II worm [5], a zero-click cyber threat targeting AI applications powered by generative models like Gemini Pro, ChatGPT 4.0 [5] [6], and LLaVA [5].


This worm exploits vulnerabilities in AI email assistants [4] [9], using self-replicating prompts to spread across interconnected GenAI ecosystems [2]. Morris II injects adversarial prompts to manipulate AI models and breach security [2], posing significant risks to applications relying on GenAI services and those utilizing the retrieval augmented generation (RAG) application to enhance queries. The worm utilizes RAG to contaminate AI models, forcing them to exfiltrate sensitive data and propagate the malware further [6]. To combat this threat, researchers recommend using countermeasures against jailbreaking techniques to detect malicious propagation patterns [7] [8]. Additionally, a non-active RAG can be employed to prevent the spread of the RAG-based worm [8], highlighting the evolving cybersecurity landscape in the age of AI and the importance of ongoing vigilance [9], advanced security protocols [9], and collaboration between developers and researchers to mitigate emerging threats [9].


