GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
2026-04-11T01:24:14Z•bd89ab1aff98fef30c750e616615544fe8e24603182545dc629bc85aec73d815
android-sdkauthorization-bypassbrowser-extensionsdeveloper-toolsdockerexploit-in-the-wildgpu-rowhammeride-compromiseiot-botnetmalwaremobile-securitynation-statepdf-exploitphishingprivilege-escalationpython-notebookransomwaresupply-chainzero-day
What happened
Multiple high-impact threats and active exploitations were reported: a new GlassWorm variant uses a Zig-based dropper embedded in an Open VSX extension to stealthily infect developer IDEs (developer-supply-chain risk); Marimo notebook remote code execution (CVE-2026-39987, CVSS 9.3) was exploited within 10 hours of disclosure; Docker Engine authorization-bypass (CVE-2026-34040, CVSS 8.8) can lead to host access; and an Adobe Reader zero-day has been exploited in the wild since December 2025. Additional incidents include a widespread Android EngageLab SDK sandbox-bypass impacting millions (incl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- bd89ab1aff98fef30c750e616615544fe8e24603182545dc629bc85aec73d815
- Enrichment time
- 2026-04-11T01:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.