GlassWorm campaign uses Zig Dropper to infect multiple developer IDEs

Rabi LakshmananApril 10, 2026Malware/Blockchain Cybersecurity researchers have warned of further evolution of the ongoing GlassWorm campaign. It employs a new Zig dropper designed to covertly infect all integrated development environments (IDEs) on a developer’s machine. The technique was discovered in an Open VSX extension named “specstudio.code-wakatime-activity-tracker” that pretends to be WakaTime, a popular tool that […]
Changing ‘just one DNA letter’ in female mice induces growth of male reproductive organs

Scientists have discovered that changing just one “letter” in the DNA of a female mouse embryo causes the development of male reproductive organs and testes. “This is a remarkable discovery because such a small change, just one letter out of about 2.8 billion DNA letters, was enough to produce a dramatic developmental outcome,” study lead […]
Artemis II returns live: NASA prepares for Artemis II crew’s dangerous return to Earth at record-breaking speed

refresh 2026-04-10T13:26:38.000Z Final review of the crew’s mission While we can’t give you the exact backstory on the contents of the crew’s dreams at this point, we can at least share some of their bedtime reflections on their historic journey. When asked what she would tell her younger self about what they do now, Christina […]
Browser extensions are the new AI consumption channel no one is talking about

While much of the discussion around AI security centers around protecting the consumption of “shadow” AI and GenAI, there is a wide open window that no one is guarding. It’s an AI browser extension. A new report from LayerX reveals just how deep this blind spot goes and why AI extensions may be the surface […]
Google deploys DBSC in Chrome 146 to block session theft on Windows

Ravi LakshmananApril 10, 2026Malware/Browser Security Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. Public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned for future Chrome releases. “This […]
Marimo RCE flaw CVE-2026-39987 exploited within 10 hours of publication

Rabi LakshmananApril 10, 2026Vulnerability/Threat Intelligence A critical security vulnerability in Marimo, an open-source Python notebook for data science and analytics, was exploited within 10 hours of its publication, according to Sysdig findings. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability that affects all versions of Marimo prior to […]
Backdoored Smart Slider 3 Pro update distributed via compromised Nextend servers

Ravi LakshmananApril 10, 2026Malware/website security An unknown attacker has hijacked the update system of the Smart Slider 3 Pro plugin for WordPress and Joomla and pushed a malicious version containing a backdoor. According to WordPress security firm Patchstack, this incident affects Smart Slider 3 Pro version 3.5.1.35 for WordPress. Smart Slider 3 is a popular […]
DNA analysis reveals that entire lower-class families were sacrificed to honor local royalty in South Korea 1,500 years ago

About 1,500 years ago, entire families were sacrificed in what is now South Korea to honor local royalty, new genetic research has found. The analysis also revealed a strong kinship system focused on women and their offspring. In a research paper published in the journal Science Advances on Wednesday (April 8), an international research team […]
Is Anthropic restricting the release of Mythos to protect the internet? Or Anthropic?

Anthropic announced this week that it has restricted the release of its latest model, called Mythos, because it is too good at finding security vulnerabilities in the software used by users around the world. Instead of making Mythos available to the public, Frontier Labs plans to share it with a group of large companies and […]
EngageLab SDK flaw exposes 50 million Android users, including 30 million crypto wallets

Ravi LakshmananApril 9, 2026Vulnerabilities / Mobile Security Details have emerged of a patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could potentially put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same device to bypass the Android security sandbox and gain […]