GlassWorm Malware Evolves to Hide in Dependencies
2026-03-16T20:51:44Z•d2cf967ca714f2e4a7ad71fcfcd14d28165ae456b452ac867979c6a89ae94e47
GlassWormactive-exploitationciscocloud-securitycredential-theftgithub-actionslivechatmalwarenation-statepatchingphishingransomwaresoftware-dependenciessupply-chaintag-poisoningvmware
What happened
DarkReading round-up (Mar 2026) highlights rising supply-chain and cloud threats plus active exploitation and large-scale patch activity. Notable items: GlassWorm variants now hide in dependencies and use new evasion techniques; a GitHub Action (xygeni) was compromised via tag poisoning and hosted an active C2; attackers are abusing LiveChat to phish credit-card and personal data; VMware Aria Operations command-injection bug is being exploited, risking cloud resource takeover; Cisco disclosed dozens of firewall flaws (including two critical CVSS-10 issues) and Microsoft released fixes for 83CV
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- d2cf967ca714f2e4a7ad71fcfcd14d28165ae456b452ac867979c6a89ae94e47
- Enrichment time
- 2026-03-16T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.