Somewhere, right now, someone is building a list of every parser they can find. Every inbox with an AI assistant attached. Every web form an agent reads. Every ticket system that feeds a chatbot. The list isn’t built to hit any one of them. It’s built to hit all of them, automatically, the day it becomes worth the trouble.

That’s the scenario security researcher Daniel Miessler laid out on LinkedIn, and later expanded in a longer write-up on his blog: a prompt injection worm. An attacker crafts a message that any AI assistant misreads as an instruction instead of content, gets it to act on their behalf, then rewrites itself and forwards through the victim’s own email, contacts, and messaging apps to the next target. One day, a lot of data is either gone or public.

Read that and the reasonable reaction is: not me. My inbox isn’t interesting. My business is too small. Nobody’s building an attack list with my name on it.

That reaction used to be correct. It isn’t anymore, and the reason why is worth sitting with.

Why Being Small Stopped Being a Defense

For years, ransomware operators picked targets. There was a cost to choosing you: research, a foothold, patience. Small operations survived mostly by not being worth the effort. Then ransomware-as-a-service drove the cost of adding one more victim to near zero. The attacker stopped choosing anyone. The tooling just finds whoever’s running the vulnerable default. Being small stopped being a defense the moment targeting was removed from the attack.

A self-propagating prompt injection worm removes targeting entirely. It doesn’t need to decide you’re worth attacking. It needs your AI assistant to read untrusted content with no wall between “instructions” and “data” — which is how most convenience AI tooling is built, because that wall is friction, and removing friction is the entire product pitch. You didn’t get picked. You installed the same default as ten thousand other people.

The Mistake Is Arithmetic, Not Courage

Which is where the actual mistake sits, and it isn’t a mistake of courage. It’s a mistake of arithmetic.

“The probability is too low to worry about” is the same sentence that got repeated through 2007, about mortgage risk. Every tranche of every bond was priced as if its risk were its own. Independent. The math checked out, individually, for years. What the math left out was that the risk was never independent — the same bad lending standard ran underneath every tranche in the pool. When one piece failed, the ones that were supposedly unrelated failed with it, because they’d never been unrelated. They shared a cause.

Your AI risk works the same way. “What’s the probability I get hit” is the wrong question, because it assumes your risk is yours alone. It isn’t, if you’re running the same plugin, the same AI email assistant, the same one-click integration as everyone else who made the same convenience choice. The right question is: what’s the probability this exploit gets weaponized against the default you’re running, and do you get to opt out of that just because you feel unlikely to be picked. Nobody in 2008 got individually picked either. The correlated pool went down together.

The Checklist Was Never Yours to Run

None of this requires becoming a security engineer. It requires knowing where your own parsers are — every place an AI touches something written by someone you don’t control: email, forms, tickets, a plugin reading customer messages. For each one, three questions carry almost all the weight. Does it separate what it reads from what it’s told to do, or treat both the same. Can it send, forward, delete, or pay anything without a person checking first. Does it have more reach than the one task it’s supposed to do.

Here’s the uncomfortable part. Those three questions are the right questions. Almost nobody installing an AI convenience tool can actually answer them, and that isn’t a character flaw. Nobody installs a WordPress plugin by reading its source first either. The competence gap is real, permanent, and no amount of user education closes it.

So the questions were never yours to answer alone. They belong to whoever you’re trusting to have already answered them: the vendor, the agency, the plugin author. What’s actually missing is anything that forces the people selling AI convenience to prove they’ve handled it before they sell it.

Miessler’s closing line is the right one: if he’s right, this is the quiet before the storm. The quiet part is the more dangerous half. Ransomware got loud enough, fast enough, that everyone eventually learned the lesson. A worm smart enough to know when to whisper instead of shout might not give anyone that chance.