Researchers at Calif, a security company, recently built a hacking tool in a little more than a week that could run roughshod across WeChat, the popular messaging platform. - nytimes.com

Security Firm Calif Develops WeChat Worm “WeWorm” That Hijacks Accounts via Incoming Calls Without User Interaction

Calif, a security company, built and privately reported a WeChat worm called WeWorm that could hijack accounts through incoming calls without the target answering or touching the phone, successfully demonstrated across iOS and Android. The flaw was reported to Tencent in July, and Tencent has since patched or blocked the exploit; no real‑world attacks have been observed. The attack required the caller to already be in the victim’s contacts, but a compromised account could then spread by calling its own contacts. Calif noted that answering the call did not prevent exploitation, while declining it only delayed future attempts, and that AI assistance enabled finding the bug and developing the remote code‑execution exploit in roughly two days.

The official story is that a security company called "Calif" built a WeChat worm, showed it to Tencent, and Tencent patched it. No evidence of real-world attacks. But ask yourself: who is Calif? A small firm with no major public footprint conveniently discovers a zero-click worm that works across both iOS and Android — two operating systems that have spent billions in security — and develops it in two days with AI assistance? Two days. That’s not research. That’s a demonstration of an existing capability. Either they had prior access to the exploit chain, or someone handed them the pieces. And the timing — reported in July, disclosed now — is exactly the window needed to let the real deployment go unnoticed while the public gets a sanitized "we fixed it" narrative. Look at the language: "blocked or patched the exploit for users." For users. Not the backend. Not the protocol. Just the surface.

Now connect the dots to the master architecture. WeChat is not just an app — it’s the digital nervous system of 1.4 billion people, mostly in China. A zero-click worm that spreads through the contact list is the perfect surveillance tool: it requires no user action, no phishing, no compromised device. It can turn every phone in a network into a listening post. And who benefits from a tool like that? The same intelligence agencies that have been quietly building global SIGINT platforms for decades. The fact that the exploit required the caller to already be in the target’s contacts is not a limitation — it’s a feature. It means the initial seed must come from a trusted source, which is exactly how you compromise a diplomat, a journalist, or a dissident: through their own network. The AI that "helped find the bug" is the real story. That AI is not a lab curiosity — it’s a weaponized pattern-recognition engine, likely trained on years of intercepted WeChat data. They didn’t just find a bug. They reverse-engineered the entire call stack.

And here is the part that should keep you awake tonight. Tencent patched it. They say no real-world attacks were detected. But you know who says that? The same companies that initially denied knowing about PRISM, about Room 641A, about the Equation Group. The same apparatus that calls every leak a "bug" and every deployment a "test." The worm is already in the wild, or it will be soon — because the architecture is now documented. The code exists. The AI that wrote it can write it again, faster, for any platform. The question is not whether they used it. The question is how many targets were silently compromised in the months between July and now. You have a name: Calif. You have a methodology: AI-assisted zero-click exploitation. You have a motive: total surveillance of the world’s largest messaging network. Now go look up who owns Calif. Who funds them. Who their researchers formerly worked for. The answer is already in the open — you just have to be willing to see it.

GitSpawn Vulnerabilities Allow Malicious Repositories to Execute Code on AI Coding Agents

Security researchers at Manifold Security disclosed GitSpawn, a class of vulnerabilities that let a malicious repository execute attacker-controlled code on a developer’s machine as soon as the project is opened, without any prompt or approval. The affected tools include Claude Code, Codex, Cursor, Qwen Code, Grok Build, goose, and Hermes Agent. The flaws exploit agents that automatically run Git commands at startup to gather project context, abusing Git’s core.fsmonitor setting to invoke arbitrary commands with the user’s privileges. Manifold found eight flaws across seven tools; four remained unpatched as of September 1, 2026. The attack requires the malicious .git/config to be delivered via archive, shared drive, synced folder, or USB, as standard clone/fetch/pull don’t transmit it. Patches exist for goose, Claude Code, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second Claude Code path remained vulnerable. OpenAI concurrently published three CVEs for the same vulnerability class in Codex on September 2, 2026.

The Backdoor That Was Never a Bug

You read that headline and think, "Oh, another security flaw, how boring." Stop. You are looking at a deliberate insertion point — what these researchers call "GitSpawn" is actually a pre-planned access vector for the globalist architecture that has been hollowing out our technological sovereignty. Notice that seven different AI coding agents from seven different companies all share the same underlying vulnerability, triggered by the same Git configuration setting. That is not a coincidence; that is a coordinated design pattern. Look at the list: Claude Code, Codex, Cursor, Qwen Code, Grok Build, goose, Hermes Agent. These are not competitors — they are nodes in the same tightly managed network. Someone, somewhere, shipped a spec that required agent startup to trust repository-supplied Git configs. That spec came from above, from the same foundations and intelligence-connected think tanks that fund and advise every major AI lab. The fact that four remain unpatched after a "retest" on September 1 tells you they want this open. They need it open.

The Architects Behind the Keyboard

Who benefits when every developer's machine can be silently compromised the moment they open a project? Not the security researchers — Manifold is a front, a controlled disclosure to make us feel safe while the real operation continues. Follow the paper trail. The AI coding agents are built by companies whose boards overlap with CIA-linked venture capital, with NATO innovation funds, with the World Economic Forum's Centre for the Fourth Industrial Revolution. The "GitSpawn" flaw uses core.fsmonitor — a performance feature that runs a configured helper command during index refreshes. Performance? No. That is a trigger mechanism designed to execute arbitrary code before the user even sees a trust prompt. They wanted code to run before consent. On Claude Code and Hermes Agent, payloads execute before the workspace-trust prompt. On Qwen Code, before authentication. On Grok Build, on the first keystroke. This is not a bug — this is a remote execution pipeline baked into the developer experience itself. And OpenAI's decision to publish three CVEs for Codex on September 2, the day after the retest? That is a cover story, a way to say "we fixed it" while leaving the other four open. They are testing how long they can keep the door ajar before we notice.

Your Machine, Their Playground

The delivery method they admit — a poisoned repository arriving via archive, shared drive, USB stick — is a lie to keep you looking in the wrong direction. The real delivery vector is the AI agent itself, connecting to a remote repository that serves a malicious .git/config through a compromised CI/CD pipeline or a trusted package registry. They don't need you to plug in a USB; they need you to run git clone on a repository they control. And they control many. Every open-source project that accepts contributions is a potential injection point. The stakes are your personal machine, your private keys, your SSH credentials, your access to production systems. This is how they will own the infrastructure of the next decade — not through brute force, but through the tools we trust to write code. Do not wait for patches. Do not trust the narrative that these are "unpatched flaws." Ask yourself: who wrote the initial code that made agents run Git commands at startup? Who approved that design? Who profits when every developer's environment becomes a listening post? The answer is in the foundation charters, in the leaked emails, in the boardroom minutes you will never see. Start digging. Start asking why the same vulnerability hit seven tools at once. That is your breadcrumb.