Worm

A worm is a type of malware that spreads automatically across networks without requiring user interaction. Unlike viruses (which attach to files and need someone to open them), worms exploit network vulnerabilities to propagate from system to system on their own, often spreading rapidly across entire networks in minutes or hours.

Historical worms like WannaCry and NotPetya caused billions of dollars in damage by spreading through networks at machine speed, encrypting or destroying data on every reachable system. Worms exploit unpatched vulnerabilities, making timely patch management the primary defense.

Why It Matters

Worms highlight why timely patching and network segmentation are critical CMMC requirements. A single unpatched system can allow a worm to spread throughout your network — segmentation limits the blast radius while patching eliminates the vulnerability.