GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

2026-04-11T07:24:16Ze8d77d9a072f63468c7b847d67f28827d0c2ef407da0bd8d988644b3214a3330
CVE-2024-41110CVE-2026-34040CVE-2026-39987IDE compromiseadobe reader zero-dayandroid sdkapt28backdoordockerengagelab sdkexploited in the wildglasswormgomarimonation-state activity','iot botnet','masjesu','chaos malware','gnpmopen-vsxpackage malwareprismexpypircerustsupply-chainwordpress pluginzig dropper

What happened

Collection of The Hacker News stories (Apr 7–10, 2026) covering multiple high-impact threats: GlassWorm’s new Zig dropper delivered via a malicious Open VSX IDE extension (targeting developer environments); a critical Marimo pre-auth RCE (CVE-2026-39987, CVSS 9.3) exploited within 10 hours of disclosure; a high-severity Docker Engine authz-bypass (CVE-2026-34040, CVSS 8.8) tied to an incomplete prior fix (CVE-2024-41110); an Adobe Reader zero-day exploited in the wild since Dec 2025; supply-chain and package ecosystem compromises (backdoored Smart Slider Pro update, malicious packages across N

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e8d77d9a072f63468c7b847d67f28827d0c2ef407da0bd8d988644b3214a3330
Enrichment time
2026-04-11T07:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.