GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

10/04/2026 0 Comments 0 tags

Cybersecurity researchers have flagged yet another evolution of the ongoing GlassWorm campaign, which employs a new Zig dropper that’s designed to stealthily infect all integrated development environments (IDEs) on a developer’s machine.

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

10/04/2026 0 Comments 0 tags

A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. The vulnerability in question is

Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

10/04/2026 0 Comments 0 tags

While much of the discussion on AI security centers around protecting ‘shadow’ AI and GenAI consumption, there’s a wide-open window nobody’s guarding: AI browser extensions.  A new report from LayerX exposes just how deep this

Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

10/04/2026 0 Comments 0 tags

Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

10/04/2026 0 Comments 0 tags

Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider

EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets

09/04/2026 0 Comments 0 tags

Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk. “This flaw

UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns

09/04/2026 0 Comments 0 tags

A previously undocumented threat cluster dubbed UAT-10362 has been attributed to spear-phishing campaigns targeting Taiwanese non-governmental organizations (NGOs) and suspected universities to deploy a new Lua-based malware called LucidRook. “LucidRook is

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

09/04/2026 0 Comments 0 tags

Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even

Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region

09/04/2026 0 Comments 0 tags

An apparent hack-for-hire campaign likely orchestrated by a threat actor with suspected ties to the Indian government targeted journalists, activists, and government officials across the Middle East and North Africa (MENA),

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025

09/04/2026 0 Comments 0 tags

Threat actors have been exploiting a previously unknown zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December 2025. The finding, detailed by EXPMON’s Haifei Li, has been