News

Yahoo Says E-Mail Worm Contained

Yahoo Inc. said Tuesday it has contained a malicious program aimed at the millions of people who use its e-mail service, which ranks as the world's largest.

The worm, dubbed "Yamanner," infected a recipient's computer as soon as the toxic e-mail was opened. It then scanned contact lists for additional targets, according to security software maker Symantec Corp.

Unlike many worms that require an attachment to be opened, the latest bug was unleashed as soon as the e-mail was opened. It burrowed into e-mail contact lists in search of addresses containing the domains yahoo.com and yahoogroups.com, according to Symantec.

Sunnyvale, California-based Yahoo said "a very small fraction" of its more than 200 million e-mail accounts were infected Monday when the problem was first identified. The worm didn't affect the next version of Yahoo's e-mail service, which remains in its test, or "beta," phase.

"We have taken steps to resolve the issue and protect our users from further attacks of this worm," Yahoo spokeswoman Kelley Podboy said. "The solution has been automatically distributed to all Yahoo Mail customers, and requires no additional action on the part of the user."

The worm arrived in the form of an e-mail containing JavaScript and contains the words "New Graphic Site" in the subject field.

As a precaution against variations on the Yamanner worm, Yahoo advised its e-mail users to update their antivirus programs and block all incoming correspondence from [email protected].

Featured

  • Microsoft Dismantles RedVDS Cybercrime Marketplace Linked to $40M in Phishing Fraud

    In a coordinated action spanning the United States and the United Kingdom, Microsoft’s Digital Crimes Unit (DCU) and international law enforcement collaborators have taken down RedVDS, a subscription based cybercrime platform tied to an estimated $40 million in fraud losses in the U.S. since March 2025.

  • Sound Wave Illustration

    CrowdStrike's Acquisition of SGNL Aims to Strengthen Identity Security

    CrowdStrike signs definitive agreement to purchase SGNL, an identity security specialist, in a deal valued at about $740 million.

  • Microsoft Acquires Osmos, Automating Data Engineering inside Fabric

    In a strategic move to reduce time-consuming manual data preparation, Microsoft has acquired Seattle-based startup Osmos, specializing in agentic AI for data engineering.

  • Linux Foundation Unites Major Tech Firms to Launch Agentic AI Foundation

    The Linux Foundation today announced the creation of a new collaborative initiative — the Agentic AI Foundation (AAIF) — bringing together major AI and cloud players such as Microsoft, OpenAI, Anthropic and other major tech companies.