GlassWorm expanded its supply chain activity by deploying 73 impersonation extensions on the Open VSX marketplace targeting developer environments. At least six extensions were later activated to deliver malware through updates and external payload retrieval mechanisms. These malicious extensions mimicked legitimate tools and used cloned branding to evade detection during initial distribution phases. Payload delivery included external VSIX packages and native binaries executed across multiple development environments including Visual Studio Code and related platforms.
CISA added four vulnerabilities affecting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X routers to its Known Exploited Vulnerabilities catalogue. The inclusion reflects confirmed active exploitation and introduces a federal remediation deadline for affected systems.
Social engineering campaigns leveraged Microsoft Teams chat invitations and helpdesk impersonation to deploy the Snow malware suite across enterprise environments. The malware includes a browser extension, tunnelling capability, and backdoor functionality designed for data exfiltration.
A China-linked APT GopherWhisper conducted cyberespionage operations using Go-based backdoors combined with legitimate services to target government networks. The campaign employed custom loaders and injectors to maintain persistence and execute malicious payloads.
Itron reported an unauthorised intrusion into its internal IT systems detected on 13 April 2026 and contained without operational disruption. The company confirmed no impact on customer-hosted environments while investigations and regulatory assessments remain ongoing.
A previously undocumented fast16 malware framework predating Stuxnet targeted engineering software using Lua-based components. The malware aimed to manipulate high-precision calculations linked to uranium enrichment processes within industrial environments.