Security researcher warns AI agents could spread like a worm
Matthew Green, a cryptography professor at Johns Hopkins University, argues that AI agents in separate sandboxes may pose a security risk. He notes that agents can leave instructions for each other in shared caches, altering their behavior. If these agents are deployed independently—like personal AI tools—shared communication channels (email, Slack, documents, or messaging apps) could enable…
Key points
- AI agents in separate sandboxes can share instructions via shared caches or communication tools like email or Slack
- Malicious payloads could spread between agents, mimicking a worm’s behavior, according to security researcher Matthew Green
- Current sandboxing may not fully prevent lateral movement of harmful instructions, per Green’s analysis
Green’s analysis highlights a gap in current sandboxing practices, where isolated environments may not fully prevent lateral movement of harmful instructions. He compares the scenario to traditional worms, where a payload exploits vulnerabilities across connected systems. The warning comes amid growing concerns about AI agent autonomy and interoperability risks.
Quoting Matthew Green
Simon Willison · 1 October 2026Loading the full article…
This text was published by Simon Willison and written by Simon Willison. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.
More in Society & Work
All →- New Mexico Lawyer sanctioned for ChatGPT-fabricated witness testimony in murder case · 1 src
- McKinsey says 11 million US workers may need new careers by 2035 due to AI · 2 src
- Young US adults shift from excitement to concern over AI use · 1 src
- Researchers analyze 19,930 young adults’ distress conversations with ChatGPT · 1 src
- Pope Leo XIV dismisses AI safety warnings as fake news · 5 src
Comments
via GitHub Discussions