Malicious VS Code extension spreads across developer tools in new GlassWorm campaign
The attack involves an Open VSX extension disguised as the popular time-tracking tool WakaTime.
2 min read
Cybersecurity Help is a global vulnerability intelligence provider. We monitor vulnerabilities in software from 60,000+ vendors and help customers prevent potential data breaches by addressing them proactively.
Request DemoThe attack involves an Open VSX extension disguised as the popular time-tracking tool WakaTime.
2 min readSince routers sit between users and AI systems, they can see all unencrypted data like API keys and user prompts.
3 min readThe flaw, tracked as CVE-2026-34621, could allow attackers to execute malicious code on affected systems.
2 min readAttackers gained access to a secondary API linked to CPUID’s website and redirected users to trojanized versions of software disguised as legitimate tools.
3 min readIn brief: Fortinet fixes a zero-day flaw, authorities disrupt the FrostArmada botnet operated by Russian APT28, and more.
15 min read