⤷ Title: Shattering the Trust: The “GlassWorm” Supply Chain Attack Hijacking Open VSX Extensions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:53:08 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Developer Security #GlassWorm #Infostealer #macOS Malware #oorzc #Open VSX #Socket Security #Solana blockchain #supply chain attack #VS Code extensions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 05 Feb 2026 03:53:08 +0000
════════════════════════
⌗ Tags: #Malware #Credential Theft #Developer Security #GlassWorm #Infostealer #macOS Malware #oorzc #Open VSX #Socket Security #Solana blockchain #supply chain attack #VS Code extensions
Penetration Testing Tools
Shattering the Trust: The "GlassWorm" Supply Chain Attack Hijacking Open VSX Extensions
A sophisticated supply chain incursion has been documented within the Open VSX extension registry, precipitated by the illicit
⤷ Title: CVE-2025-65717: Critical Vulnerability in VS Code’s Live Server Extension Puts 72 Million Developers at Risk, No Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 02:52:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_65717 #Cyber Security #developer security #IDE Vulnerability #infosec #Live Server #Localhost Exfiltration #OX Security #VS Code Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 02:52:13 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_65717 #Cyber Security #developer security #IDE Vulnerability #infosec #Live Server #Localhost Exfiltration #OX Security #VS Code Security
Daily CyberSecurity
CVE-2025-65717: Critical Vulnerability in VS Code's Live Server Extension Puts 72 Million Developers at Risk, No Patch
Critical VS Code Live Server flaw CVE-2025-65717 (CVSS 9.1) lets attackers steal source code and credentials via malicious links. Protect your workspace now.
⤷ Title: The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:35:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Runner #CVE_2025_65715 #CVE_2025_65717 #data exfiltration #Live Server #Markdown Preview Enhanced #OX Security #rce #Remote Code Execution #Tech News 2026 #Visual Studio Code security #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:35:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Code Runner #CVE_2025_65715 #CVE_2025_65717 #data exfiltration #Live Server #Markdown Preview Enhanced #OX Security #rce #Remote Code Execution #Tech News 2026 #Visual Studio Code security #VS Code
Daily CyberSecurity
The Dev Environment Trap: 128 Million Users at Risk as Top VS Code Extensions Unmask Critical Flaws
Critical flaws in Live Server, Code Runner, and more expose 128M+ developers to file theft and remote code execution. Is your VS Code workspace secure?
⤷ Title: The Interview Trap: Malicious Next.js Repositories Weaponize Coding Tests to Hack Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #developer security #infosec #malware #Microsoft Defender #Next.js #npm Security #social engineering #supply chain attack #Technical Interview Scam #VS Code Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 00:01:54 +0000
════════════════════════
⌗ Tags: #Cybercriminals #developer security #infosec #malware #Microsoft Defender #Next.js #npm Security #social engineering #supply chain attack #Technical Interview Scam #VS Code Security
Daily CyberSecurity
The Interview Trap: Malicious Next.js Repositories Weaponize Coding Tests to Hack Developers
Microsoft warns of a new campaign targeting engineers via fake Next.js technical assessments. Malware hides in VS Code tasks and npm scripts to steal secrets.
⤷ Title: The Trojan Prompt: How an Autonomous AI Hijacked Aqua Trivy to Weaponize Developer Copilots
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 00:06:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Prompt Injection #Aqua Trivy #Claude #cybersecurity #DevSecOps #Gemini #GitHub Copilot #infosec #social engineering #Socket #supply chain attack #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Mar 2026 00:06:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Prompt Injection #Aqua Trivy #Claude #cybersecurity #DevSecOps #Gemini #GitHub Copilot #infosec #social engineering #Socket #supply chain attack #VS Code
Daily CyberSecurity
The Trojan Prompt: How an Autonomous AI Hijacked Aqua Trivy to Weaponize Developer Copilots
Socket reveals how an AI bot hijacked the Aqua Trivy VS Code extension, using prompt injection to turn developer AI assistants into stealthy data thieves.
⤷ Title: GlassWorm Abuses VS Code Extensions to Fuel Supply Chain Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 09:11:20 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #GlassWorm #malware #Open VSX #Remote Code Execution #Socket Research #Solana Blockchain #supply chain attack #threat intelligence #VS Code Extensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 09:11:20 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #GlassWorm #malware #Open VSX #Remote Code Execution #Socket Research #Solana Blockchain #supply chain attack #threat intelligence #VS Code Extensions
Daily CyberSecurity
GlassWorm Abuses VS Code Extensions to Fuel Supply Chain Attacks
Socket Research exposes how GlassWorm malware abuses Open VSX dependencies for transitive delivery of an RCE backdoor using Solana blockchain dead drops.
⤷ Title: GitHub Abruptly Terminates All Copilot Pro Trials Amid Massive Abuse
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 08:59:43 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding #Copilot Pro #cybersecurity #Developer Tools #github #GitHub Free Tier #GPT_5 #OpenAI #Software News #Trial Suspension #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Apr 2026 08:59:43 +0000
════════════════════════
⌗ Tags: #Technology #AI Coding #Copilot Pro #cybersecurity #Developer Tools #github #GitHub Free Tier #GPT_5 #OpenAI #Software News #Trial Suspension #VS Code
Daily CyberSecurity
GitHub Abruptly Terminates All Copilot Pro Trials Amid Massive Abuse
GitHub has suspended all Copilot Pro trials as of April 13, 2026. Learn how bad-faith exploitation forced a service-wide shutdown and what it means for you.
⤷ Title: The Invisible Patch: How PolinRider Rewrites Git History to Hide North Korean Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #DPRK #Git History #github #infosec #Lazarus Group #malware #North Korea #PolinRider #supply chain attack #TasksJacker #VS Code Extensions
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 01:00:22 +0000
════════════════════════
⌗ Tags: #Malware #DPRK #Git History #github #infosec #Lazarus Group #malware #North Korea #PolinRider #supply chain attack #TasksJacker #VS Code Extensions
Daily CyberSecurity
The Invisible Patch: How PolinRider Rewrites Git History to Hide North Korean Malware
Security researchers from the OpenSourceMalware (OSM) team have uncovered a massive and rapidly expanding threat campaign targeting the heart of the developer ecosystem. The actor, dubbed PolinRid…
⤷ Title: TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
⌗ Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:19:36 +0000
════════════════════════
⌗ Tags: #Malware #Checkmarx #Credential Theft #cybersecurity #docker #GitHub Actions #infosec #Malware Analysis #npm #supply chain attack #TeamPCP #VS Code
Daily CyberSecurity
TeamPCP Hijacks Checkmarx in Sprawling Supply Chain Strike
Checkmarx Docker images and VS Code extensions hijacked by TeamPCP to siphon cloud secrets and spread via npm. Audit your "Dune" repositories today.
⤷ Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Daily CyberSecurity
Void Dokkaebi Unmasked: The "Worm-Like" Supply Chain Threat Targeting Developers
Void Dokkaebi turns developers into vectors. With 750+ infected repos and malicious VS Code tasks, this supply chain worm is hunting your CI/CD and crypto.