Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data

2026-04-12T01:24:17Z8b22f68ac85e97122c0737de47c7e317b15574249ea1713e488b170d9db65a1f
CVE-2026-34040CVE-2026-39987adobe-readerapt28backdoorbotnetcomfyuicrypto-walletsddosdockerengagelab-sdkglasswormgpubreachiotmalicious-packagesmarimomobile-sdknpm-pypi-go-rustopen-vsxprismexremote-code-executionsoftware-supply-chainsupply-chain-compromisezero-dayzig-dropper

What happened

A surge of high-impact security events and research was reported, spanning active zero-day exploitation, supply‑chain compromises, large-scale SDK/third‑party flaws, and nation‑state campaigns. Notable items: Marimo pre-auth RCE (CVE-2026-39987, CVSS 9.3) was exploited within 10 hours of disclosure; Docker Engine authorization‑bypass (CVE-2026-34040, CVSS 8.8) was disclosed; an Adobe Reader zero‑day has been exploited since Dec 2025. Supply‑chain and developer‑tool risks include a backdoored Smart Slider 3 Pro update, a malicious Open VSX extension delivering a Zig dropper (GlassWorm) that can

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
8b22f68ac85e97122c0737de47c7e317b15574249ea1713e488b170d9db65a1f
Enrichment time
2026-04-12T01:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.