GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

2026-04-10T19:24:16Z781b41e8ca4850ebba2a070d9fb0727f321fff675af5dff13f7c5abd7a49909f
adobe-reader-zero-dayandroid-sdk-vulnerabilityapt28comfyui-cryptominingdockerengagelab-sdkglasswormgogpubreachide-compromiseiot-botnetirAN-linked-actorsmarimomasjesunpmopen-vsxplc-ot-attacksprismexpypirowhammerrustsoftware-update-poisoningsupply-chainwaka-time-impersonationzig-dropper

What happened

Collection of security reports describing an active, high-risk threat landscape: a GlassWorm campaign using a new Zig dropper hidden in an Open VSX extension to infect developer IDEs; a critical Marimo RCE (CVE-2026-39987) exploited within hours of disclosure; a Docker Engine authorization-bypass (CVE-2026-34040); an actively exploited Adobe Reader zero-day used in malicious PDFs; backdoored WordPress/Joomla plugin updates (Smart Slider 3 Pro); a widespread EngageLab Android SDK flaw exposing millions of users; supply-chain and repository poisoning across npm/PyPI/Go/Rust; targeted APT (APT28)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
781b41e8ca4850ebba2a070d9fb0727f321fff675af5dff13f7c5abd7a49909f
Enrichment time
2026-04-10T19:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.