GlassWorm evolves with Zig dropper to infect multiple developer tools
The GlassWorm campaign uses a Zig-based dropper hidden in a fake IDE extension to infect developer tools and compromise systems. The GlassWorm campaign, active since 2025, has evolved from malicious n...
Related Vulnerabilities
- CVE-2026-35595: Vikunja vulnerable to Privilege Escalation via Project Reparenting HIGH
- CVE-2026-2712: The WP-Optimize plugin for WordPress is vulnerable to unauthorized access of functionality due to mi MEDIUM
- CVE-2026-35577: Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. P MEDIUM
- CVE-2026-4154: GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow HIGH
- CVE-2026-4305: The Royal WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to Reflected Cross-Si MEDIUM
Related Coverage
Threat Actors