Not even webmail is safe from internet worms.

The new worm, named yamann, uses javascript that is embedded in the email messages to spread, according to Sophos.

Yahoo has already fixed the exploit and says their users need not take further action.

Howevers, says ISC:

Software developers, and webmasters alike should take this as a warning, new exploits will be coming that will use javascript and Ajax-like behavior to spread. The current worm could be readily modified to spread across many systems that do not escape javascript when displaying data from a foreign source.

