Related Threat Clusters
-
Jscrambler npm Package Compromised in Supply Chain Attack
On July 11, 2026, multiple malicious versions of the jscrambler npm package were published, exploiting a compromised npm publishing credential. The affected versions (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0) included…
18 articles · Updated July 12, 2026 -
Glassworm Botnet Targeting Developers Disrupted by CrowdStrike and Google
The Glassworm botnet, which has targeted software developers since early 2025, was taken down in a coordinated operation by CrowdStrike, Google, and the Shadowserver Foundation on May 26, 2026. This botnet utilized…
30 articles · Updated May 27, 2026 -
GhostApproval Vulnerability Exposes AI Coding Assistants to Remote Code Execution
A vulnerability named GhostApproval has been discovered in six major AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This flaw allows…
17 articles · Updated July 8, 2026 -
Critical Vulnerability in MCP Protocol Exposes 200,000 AI Servers to Remote Code Execution
A report by OX Security has identified a critical vulnerability in the Model Context Protocol (MCP) developed by Anthropic, potentially exposing over 200,000 AI servers to remote code execution. The flaw lies in the…
12 articles · Updated April 16, 2026 -
Design Flaw in MCP Endangers 200K Servers, Researchers Warn
A design flaw in Anthropic's Model Context Protocol (MCP) threatens approximately 200,000 servers with complete takeover, according to the Ox research team. Despite multiple requests for a patch, Anthropic maintains…
2 articles · Updated April 16, 2026 -
Malicious Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Credentials
Bitdefender researchers have uncovered a malicious extension for the Windsurf IDE that deploys a multi-stage NodeJS stealer via the Solana blockchain. Disguised as a legitimate R language support tool for Visual Studio…
3 articles · Updated March 19, 2026 -
GlassWorm Malware Exploits OpenVSX Extension to Infect Multiple IDEs
A malicious extension named code-wakatime-activity-tracker has been identified on the OpenVSX marketplace, designed to spread the GlassWorm malware across multiple integrated development environments (IDEs) including VS…
3 articles · Updated April 10, 2026 -
Developers Distrust AI Code Yet Neglect Verification
A survey conducted by Sonar reveals that 96% of software developers doubt the functional correctness of AI-generated code, while only 48% consistently verify such code before committing it. The findings are based on…
2 articles · Updated January 10, 2026 -
Novee Unveils Agentic Fix for Automated Vulnerability Remediation
Novee has launched Agentic Fix, a new feature that integrates validated exploit findings into AI coding agents, streamlining the vulnerability remediation process. This enhancement allows security teams to generate…
9 articles · Updated May 26, 2026 -
Rogue MCP Servers Exploit Vulnerability in Cursor Code Editor
Security researchers have identified a vulnerability in Cursor, an AI-powered code editor, that allows rogue Model Context Protocol (MCP) servers to inject malicious code into its internal browser. This exploit can…
2 articles · Updated November 17, 2025
Recent Intelligence Reports
- jscrambler npm hijack sweeps AI coding tool config keys — Aiweekly.Co · July 12, 2026
- GhostApproval — www.wiz.io · July 10, 2026
- Vulnerability in coding agents: access to arbitrary files via symlinks — Heise.De · July 9, 2026
- New GhostApproval Vulnerability Affects Amazon Q, Claude Code, Cursor, and Other AI Agents — Cybersecuritynews · July 9, 2026
- CrowdStrike and Google have blocked 'Glassworm,' a botnet targeting open — Gigazine · May 28, 2026
- CrowdStrike and Google dismantle Glassworm botnet that targeted developers ... — Cryptobriefing · May 27, 2026
- Glassworm botnet that targeted OS devs smashed to pieces — Computerweekly · May 27, 2026
- Pentest Agent Suite — Cybersecuritynews · May 25, 2026