Security news aggregator

Latest coverage for Worm

Stay current on the latest Worm threats. Expert analyses, emerging risks, and prevention tips for robust information security on our Worm tag page.

112 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Worm is a type of malware that replicates itself in order to spread to other computers. Unlike a virus, it does not need to attach itself to an existing program and typically exploits network vulnerabilities to travel autonomously. In the context of information security, worms pose a significant threat due to their ability to replicate quickly and in large volumes, consuming computing resources and potentially delivering harmful payloads.

Once a worm infiltrates a system, it can perform a variety of malicious activities. These may include stealing sensitive data, installing backdoors to allow remote control, or damaging the host system's functionality. Effective countermeasures against worms include implementing strong network security practices, using up-to-date antivirus software, and regularly applying software patches to close any vulnerabilities that worms could exploit.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 112 Filtered view

A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to protect your organization. The post Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign appeared first on Microsoft Security Blog.

Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted

Latest Mini Shai-Hulud Worm Steals Credentials, Includes Wiper, Now Open SourceA new Shai-Hulud variant has infected multiple npm repositories and jumped to other widely used JavaScript and Python packages. Designed to rapidly propagate, the worm steals over 100 different types of credentials and can wipe systems, including if developers try to delete it.

Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to TeamPCP from the environments

Loading more headlines...