-
-
-
-
-
-
-
-
Glassworm Takedown: How CrowdStrike, Google, and Shadowserver Killed the “Unkillable” Developer Botnet
Yesterday at 14:00 UTC, CrowdStrike, Google, and the Shadowserver Foundation simultaneously struck all four C2 channels of the Glassworm botnet — including a Solana blockchain wallet takeover and BitTorrent DHT eclipse attack. The botnet the security community called unkillable is silent. ZOMBI is still running on infected machines and 18 months of stolen credentials remain in attacker hands.
-
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credentials as #1 Breach Vector — And Only 26% of CISA KEV Flaws Were Patched
The Verizon 2026 Data Breach Investigations Report analyzed 22,052 incidents and 12,195 confirmed breaches — the largest dataset in the report’s history. The headline finding: vulnerability exploitation has overtaken stolen credentials as the #1 initial access vector in breaches for the first time ever. Only 26% of CISA KEV vulnerabilities were fully remediated in 2025. Median remediation time grew to 43 days while exploitation timelines shrank to 5 days. Ransomware appeared in 44% of all breaches. Supply chain attacks doubled. Here is what every enterprise security team needs to act on immediately.
-
TanStack → Nx Console → GitHub: How One Poisoned VS Code Extension Breached GitHub, OpenAI, and Mistral AI in 18 Minutes
TeamPCP published a poisoned Nx Console VS Code extension for 18 minutes on May 18, 2026. In that window, VS Code auto-updated 2.2 million installs. One was a GitHub employee — giving TeamPCP access to 3,800 internal GitHub repositories. OpenAI, Mistral AI, and Grafana Labs were simultaneously hit via the same TanStack npm supply chain cascade. This is the Mini Shai-Hulud campaign operating at SolarWinds scale.
