Dozens of Open VSX Extension Clones Linked to GlassWorm Malware

2026-04-28T13:24:08Z37a476b4c82396d586b6dc1c8af9c26d1d712df68b1005d6ff2f2b6d9407efe4
AI securityGlassWormIncomplete patchMedtronicOpen VSXOpenSSHPhantomRPCRussiaShinyHuntersSignal phishingWindowsYadeaZero Motorcyclesagentic AIcertificate parsingdata breachelectric vehicle vulnerabilitiesextension clonesmalwareprivilege escalationprompt injectionroot accesssecurity startupssupply chainzero-click

What happened

This SecurityWeek feed reports multiple active and emerging threats: researchers linked over 70 cloned Open VSX extensions to GlassWorm malware, indicating a supply-chain/backdoor risk from extension clones; a new unpatched PhantomRPC technique can let a fake RPC server impersonate services and escalate to SYSTEM on Windows; an incomplete Windows patch leaves systems open to zero‑click attacks (historically exploited by APT28); an OpenSSH 15‑year flaw could allow full root shell access via certificate principal parsing; vulnerabilities in Zero Motorcycles and Yadea electric two‑wheelers pose e

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
37a476b4c82396d586b6dc1c8af9c26d1d712df68b1005d6ff2f2b6d9407efe4
Enrichment time
2026-04-28T13:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Dozens of Open VSX Extension Clones Linked to GlassWorm Malware · Baitaphish