GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
2026-04-11T07:24:16Z•e8d77d9a072f63468c7b847d67f28827d0c2ef407da0bd8d988644b3214a3330
CVE-2024-41110CVE-2026-34040CVE-2026-39987IDE compromiseadobe reader zero-dayandroid sdkapt28backdoordockerengagelab sdkexploited in the wildglasswormgomarimonation-state activity','iot botnet','masjesu','chaos malware','gnpmopen-vsxpackage malwareprismexpypircerustsupply-chainwordpress pluginzig dropper
What happened
Collection of The Hacker News stories (Apr 7–10, 2026) covering multiple high-impact threats: GlassWorm’s new Zig dropper delivered via a malicious Open VSX IDE extension (targeting developer environments); a critical Marimo pre-auth RCE (CVE-2026-39987, CVSS 9.3) exploited within 10 hours of disclosure; a high-severity Docker Engine authz-bypass (CVE-2026-34040, CVSS 8.8) tied to an incomplete prior fix (CVE-2024-41110); an Adobe Reader zero-day exploited in the wild since Dec 2025; supply-chain and package ecosystem compromises (backdoored Smart Slider Pro update, malicious packages across N
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- e8d77d9a072f63468c7b847d67f28827d0c2ef407da0bd8d988644b3214a3330
- Enrichment time
- 2026-04-11T07:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.