Daily digest,
GlassWorm Campaign Targets Developers with Malicious VS Code… (+1 more)
Vulnerabilities
Critical KVM Zero-Day Allows VM Escape and Host Root Access
Vercel has confirmed a critical KVM zero-day vulnerability discovered by researcher Paulos Yibelo, enabling guest virtual machines to escape and gain root access on the host system. The flaw affects KVM, a widely used Linux virtualization technology, but specific technical details and affected versions have not been disclosed. The vulnerability could allow attackers to compromise entire cloud environments by gaining control over all tenants and virtual machines running on a server. No confirmed exploitation has been reported yet, and no CVE has been assigned. The discovery has sparked debate over the $50,000 bug bounty awarded to Yibelo, with some experts suggesting it is insufficient given the potential impact. Vercel's Sandbox environment, which utilizes KVM and Firecracker microVMs, is particularly at risk. A full technical write-up is expected to provide more details in the future.
Vulnerability · 2 sources · score 56
Threat actors and malware
GlassWorm Campaign Targets Developers with Malicious VS Code Extensions
A cluster of malicious Visual Studio Code extensions linked to the GlassWorm threat actor was uncovered, affecting thousands of developers. These extensions, disguised as color themes, contain obfuscated JavaScript loaders that can retrieve secondary payloads. The Socket Threat Research team identified two confirmed malicious extensions and several high-risk, cluster-linked identities through Git history analysis. The malicious extensions, including Coca-Cola Christmas and Aurora Borealis Studio Theme, have accumulated over 8,000 installs on the Visual Studio Marketplace. The malware uses techniques such as AES-256-CBC decryption and Solana blockchain transaction memos to communicate with command and control infrastructure. Organizations are advised to review their installed extensions, particularly those from the Visual Studio Marketplace and Open VSX. Immediate isolation of affected hosts is recommended if malicious activity is detected. The campaign exploits the software supply chain to target developers and steal sensitive data.
Malware · 2 sources · score 63 · Cosmic Nebula Themes, Glassworm
New on leak sites
26 victims listed on ransomware leak sites by 11 groups in the 24 hours before this issue. The most active:
Also moving
- APT groups: ShinyHunters, APT41
- Vulnerabilities: Arbitrary File Access Vulnerability, Path Traversal, Apache ActiveMQ RCE Vulnerability, Buffer Over-read In Marshal Deserialization
- CVEs: CVE-2026-21589, CVE-2019-13990, CVE-2020-37268, CVE-2021-26086, CVE-2022-1471
- Ransomware groups: Asahi, BlackLock, Booba, BYOD, Clop
- Malware: Blackshades, Chisel, ClickFix, Cosmic Nebula Themes
- Campaigns: Blinder Tunnel
Get the next one by email
The digest is free and arrives every morning. One click to leave.
A free account turns the digest into a personal watchlist: choose what you want to follow.