GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
2026-04-10T19:24:16Z•781b41e8ca4850ebba2a070d9fb0727f321fff675af5dff13f7c5abd7a49909f
adobe-reader-zero-dayandroid-sdk-vulnerabilityapt28comfyui-cryptominingdockerengagelab-sdkglasswormgogpubreachide-compromiseiot-botnetirAN-linked-actorsmarimomasjesunpmopen-vsxplc-ot-attacksprismexpypirowhammerrustsoftware-update-poisoningsupply-chainwaka-time-impersonationzig-dropper
What happened
Collection of security reports describing an active, high-risk threat landscape: a GlassWorm campaign using a new Zig dropper hidden in an Open VSX extension to infect developer IDEs; a critical Marimo RCE (CVE-2026-39987) exploited within hours of disclosure; a Docker Engine authorization-bypass (CVE-2026-34040); an actively exploited Adobe Reader zero-day used in malicious PDFs; backdoored WordPress/Joomla plugin updates (Smart Slider 3 Pro); a widespread EngageLab Android SDK flaw exposing millions of users; supply-chain and repository poisoning across npm/PyPI/Go/Rust; targeted APT (APT28)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 781b41e8ca4850ebba2a070d9fb0727f321fff675af5dff13f7c5abd7a49909f
- Enrichment time
- 2026-04-10T19:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.