GlassWorm Malware Evolves to Hide in Dependencies

2026-03-16T20:51:44Zd2cf967ca714f2e4a7ad71fcfcd14d28165ae456b452ac867979c6a89ae94e47
GlassWormactive-exploitationciscocloud-securitycredential-theftgithub-actionslivechatmalwarenation-statepatchingphishingransomwaresoftware-dependenciessupply-chaintag-poisoningvmware

What happened

DarkReading round-up (Mar 2026) highlights rising supply-chain and cloud threats plus active exploitation and large-scale patch activity. Notable items: GlassWorm variants now hide in dependencies and use new evasion techniques; a GitHub Action (xygeni) was compromised via tag poisoning and hosted an active C2; attackers are abusing LiveChat to phish credit-card and personal data; VMware Aria Operations command-injection bug is being exploited, risking cloud resource takeover; Cisco disclosed dozens of firewall flaws (including two critical CVSS-10 issues) and Microsoft released fixes for 83CV

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
d2cf967ca714f2e4a7ad71fcfcd14d28165ae456b452ac867979c6a89ae94e47
Enrichment time
2026-03-16T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.