GlassWorm campaign uses Zig Dropper to infect multiple developer IDEs

Rabi LakshmananApril 10, 2026Malware/Blockchain Cybersecurity researchers have warned of further evolution of the ongoing GlassWorm campaign. It employs a new Zig dropper designed to covertly infect all integrated development environments (IDEs) on a developer’s machine. The technique was discovered in an Open VSX extension named “specstudio.code-wakatime-activity-tracker” that pretends to be WakaTime, a popular tool that […]

Browser extensions are the new AI consumption channel no one is talking about

While much of the discussion around AI security centers around protecting the consumption of “shadow” AI and GenAI, there is a wide open window that no one is guarding. It’s an AI browser extension. A new report from LayerX reveals just how deep this blind spot goes and why AI extensions may be the surface […]

Google deploys DBSC in Chrome 146 to block session theft on Windows

Ravi LakshmananApril 10, 2026Malware/Browser Security Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. Public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned for future Chrome releases. “This […]

Marimo RCE flaw CVE-2026-39987 exploited within 10 hours of publication

Rabi LakshmananApril 10, 2026Vulnerability/Threat Intelligence A critical security vulnerability in Marimo, an open-source Python notebook for data science and analytics, was exploited within 10 hours of its publication, according to Sysdig findings. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability that affects all versions of Marimo prior to […]

Backdoored Smart Slider 3 Pro update distributed via compromised Nextend servers

Ravi LakshmananApril 10, 2026Malware/website security An unknown attacker has hijacked the update system of the Smart Slider 3 Pro plugin for WordPress and Joomla and pushed a malicious version containing a backdoor. According to WordPress security firm Patchstack, this incident affects Smart Slider 3 Pro version 3.5.1.35 for WordPress. Smart Slider 3 is a popular […]

EngageLab SDK flaw exposes 50 million Android users, including 30 million crypto wallets

Ravi LakshmananApril 9, 2026Vulnerabilities / Mobile Security Details have emerged of a patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could potentially put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same device to bypass the Android security sandbox and gain […]