Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    India’s Cockroach Movement Delivers a Blow to the BJP – Foreign Policy

    July 23, 2026

    Why Abderrahim Fakir’s death reignited Italy’s police accountability debate | News

    July 23, 2026

    Moscow-linked nuclear project in northwest Germany gets green light – POLITICO

    July 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • India’s Cockroach Movement Delivers a Blow to the BJP – Foreign Policy
    • Why Abderrahim Fakir’s death reignited Italy’s police accountability debate | News
    • Moscow-linked nuclear project in northwest Germany gets green light – POLITICO
    • Employer’s national insurance should be cut for all under-25s, MPs say
    • Lobbying giant filmed offering reporter payment for flattering client coverage in national press | Lobbying
    • Lego’s Donkey Kong arcade machine lets Mario jump endless barrels — Miyamoto is reportedly happy
    • Attackers Combo Up Evasion Tactics for BEC Phishing
    • Benchmark Raises Hut 8 Price Target After Bitcoin Miner Signs $9.8 Billion AI Data Center Deal
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Thursday, July 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    What the Worm Era Can Teach Us About AI Security

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 22, 2026 Cybersecurity No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Twenty-five years ago, the Code Red worm emerged as one of the first internet-scale cybersecurity incidents, exploiting vulnerable Microsoft IIS servers and spreading rapidly across organizations worldwide. More than just a worm, it exposed a security reality that remains true today: organizations cannot secure what they do not know they have.

    In this Partner Perspective discussion, BeyondTrust CTO Marc Maiffret reflects on discovering Code Red in 2001, and explains how the worm helped shape modern approaches to vulnerability management, asset visibility, patching, and security operations.

    Joined by longtime cybersecurity journalist Dennis Fisher and BeyondTrust Field CTO James Maude, the conversation revisits the pivotal moment when Code Red emerged and examines the lasting impact of worm-era attacks on today’s security practices. The discussion then turns to one of the most significant technology shifts since the rise of the internet: artificial intelligence.

    Related:Inc Ransomware Exploits SonicWall SMA Zero-Days

    As organizations rush to deploy AI tools, AI agents, and AI-powered workflows, security teams face many of the same challenges that accompanied previous waves of technology adoption. Visibility, governance, and understanding what is actually running in the environment remain foundational security requirements that are as important now as they were when Code Red was discovered.

    In this video you will learn how lessons from the Code Red worm 25 years ago can help today’s security leaders think about AI security, shadow AI, attack surface management, and the importance of identifying and securing emerging technologies before attackers do.

    Continue Exploring

    For additional insights, guidance, and research related to the topics discussed in this video, visit:

    Continue the Conversation

    Check out the other articles in the Code Red series:

    Transcript:

    [01:00:00] James: Today I’m delighted to be joined by my friend and colleague Marc Maiffret, CTO of BeyondTrust. Welcome, Marc.

    [01:00:05] Marc: Hey man, good to be hanging again.

    [01:00:07] James: And we’re also joined by the legend that is Dennis Fisher of Decipher fame. So Dennis, welcome.

    [01:00:12] Dennis: Great to be here, thanks for having me.

    Related:Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear

    [01:00:14] James: And Dennis, as our resident cyber historian — you’ve been a journalist covering the scene for a very long time — do you want to let the audience know what we’re gathered to talk about today?

    [01:00:23] Dennis: I would love to, James. Yeah, we are here to talk about the twenty-fifth anniversary of the Code Red worm, which Marc co-discovered — I guess that’s the right word, Marc?

    [01:00:34] Dennis: That was a different time in security. Security kind of didn’t exist at that point — both the security community and the industry. The worm itself has this outsized place in cybersecurity history, I think, and there are a number of reasons for that. One, I think the name itself gave it a lot of the notoriety it got immediately. And then it was kind of the first big internet-wide worm. There had been a few smaller ones before, like “I Love You” and the Anna Kournikova worm, but those were email worms. Code Red was a network worm that had some DDoS capabilities as well. It was one of the first big ones that kind of broke out of the little security world we lived in at the time.

    [01:01:23] Dennis: What do you remember about that time, leading up to the discovery of Code Red?

    [01:01:30] Marc: Myself and Ryan Permeh — it was essentially a Friday night after work. We got a couple of different emails from two different customers saying, “Hey, my web server is doing something weird.” They couldn’t really explain it. We started looking at the packet captures and at first didn’t think much of it. But then we came across these outbound connections happening in a way that seemed abnormal. Pulling onthose threads in the packet captures led us to finding that, yes, this was not just somebody exploiting a vulnerability as a standard exploit. When we actually got into the payload — when Ryan got into it, disassembling the code to figure out the behavior — we were like, wait a minute, this is not your standard exploit. This is something different.

    Related:Claude Flaw Automatically Sends Malicious Prompts to AI Agents

    [01:02:24] And then of course, the name Code Red — Code Red was this amazing soda at the time — and very fitting, because one part of the payload would literally post a message on the website saying “Hacked by Chinese…” etc. It just all fit.

    [01:02:43] We basically just posted our analysis on some security mailing lists, not really thinking a whole lot about it, because nothing like this had happened in this way. And then obviously it went crazy from there. Later that week, I got a phone call from somebody higher up in marketing for Pepsi. He was like, “Hey, it’s kind of weird being associated with this bad worm thing, but we’re selling a lot of soda.” They noticed there was a Pepsi distribution site a few blocks from our office, and offered to send us free soda — and they did that for I don’t know how many months, until we were like, “Just stop. We can’t drink anymore.”

    [01:03:32] [Marc opens a Code Red soda] But by the way, this is where I’ll do the old crack it open here…

    [01:03:45] Dennis: You know, I haven’t had this in like twenty-five years, Marc.

    [01:03:48] Dennis: I don’t know, man… God, that’s good. I hate to say it, it’s really good.

    [01:03:52] James: So, Code Red exploited a default-on service that many organizations probably didn’t even know they were running, didn’t know was misconfigured, didn’t know there was a patch available for. What’s today’s equivalent — the visibility blind spot just waiting to be exploited in organizations?

    [01:04:10] Marc: Everything I’ve seen in the rush for businesses to adopt AI. And it completely makes sense. If you’re not adopting AI and enabling your business on it, you will fall behind. And I think, in that rush to stay competitive and adopt things quickly (same as during the internet boom), a lot of people are rushing in and security is lagging behind. So I think the question is how you think, in a first-principles way, around AI security. In some ways, it’s those same principles from Code Red: do you even know what you have? That’s step one in security.

    [01:04:53] I think positively about AI. There will be a period of turmoil and chaos as everybody figures out the new normal, but I think we’ll level-set. And I think conversations like this are critical. You look back, and the patterns are what you’re looking for. And I think we see a lot of these same patterns. The more we talk about them, the more chance that people are going to do something about them.

    About BeyondTrust:

    BeyondTrust is the global leader in privilege-centric identity security protecting Paths to Privilege™. Identity alone doesn’t create risk. Privilege does. As human, machine, and AI agent identities explode across every environment, BeyondTrust is the only company built to discover, control, and secure privilege across all of them from a single platform. Trusted by 20,000+ customers, including 75 of the Fortune 100, and recognized as a multi-category leader by top industry analysts, BeyondTrust reframes identity security from a management problem into a strategic advantage. Learn more at www.beyondtrust.com.

    Era Security Teach Worm
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Attackers Combo Up Evasion Tactics for BEC Phishing

    Upbound says hack caused $13 million in fraudulent Acima leases

    New CISO appointments 2026 | CSO Online

    AI, security operations and the new race against time

    Fake Bahrain Alert App Deploys Android Surveillance Malware

    Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    India’s Cockroach Movement Delivers a Blow to the BJP – Foreign Policy

    July 23, 2026

    Why Abderrahim Fakir’s death reignited Italy’s police accountability debate | News

    July 23, 2026

    Moscow-linked nuclear project in northwest Germany gets green light – POLITICO

    July 23, 2026

    Employer’s national insurance should be cut for all under-25s, MPs say

    July 23, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    India’s Cockroach Movement Delivers a Blow to the BJP – Foreign Policy

    July 23, 2026

    Why Abderrahim Fakir’s death reignited Italy’s police accountability debate | News

    July 23, 2026

    Moscow-linked nuclear project in northwest Germany gets green light – POLITICO

    July 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.