惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
爱范儿
爱范儿
小众软件
小众软件
MyScale Blog
MyScale Blog
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
SegmentFault 最新的问题
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
V
V2EX
量子位
云风的 BLOG
云风的 BLOG
A
About on SuperTechFans
阮一峰的网络日志
阮一峰的网络日志
Last Week in AI
Last Week in AI
Martin Fowler
Martin Fowler
C
Check Point Blog
月光博客
月光博客

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY Frontier AI models reap rapid discovery of security vulnerabilities
Coordinated operation takes down Glassworm botnet
David Jones · 2026-05-27 · via Cybersecurity Dive - Latest News

An article from site logo

The botnet began in early 2025, targeting software developers across the open-source supply chain.

Published May 27, 2026

CrowdStrike booth at RSA Conference in San Francisco.

RSA Conference attendees mingle at CrowdStrike's booth at the Moscone Center on April 27, 2023, in San Francisco. CrowdStrike led the takedown of the Glassworm botnet on May 26, 2026. Matt Kapko/Cybersecurity Dive

The Glassworm botnet, a global operation targeting software developers through the open-source supply chain, was disrupted Wednesday in a coordinated takedown led by CrowdStrike.

All four of the botnet’s command-and-control channels were targeted simultaneously, effectively disconnecting them from their infected computers and leaving them unable to deliver malicious payloads, according to a blog post from the cybersecurity company. 

Since early 2025, Glassworm’s operators have been targeting developers, who have access to source code repositories, continuous integration/continuous delivery pipelines, package registries and cloud platforms, CrowdStrike said. 

The botnet had a full range of malicious capabilities, including credential harvesting and data theft. It included a Node.js remote access tool called GlasswormRAT. 

CrowdStrike worked in a coordinated effort with Google and the Shadowserver Foundation to go after Glassworm, which the company said was likely based in Russia. 

More than 300 GitHub repositories were poisoned during the Glassworm campaign, which harvested credentials from prior attacks. 

Malicious code was introduced using compromised npm and Python packages. In addition, Trojanized VS Code extensions were published to the Open VSX marketplace. 

Researchers said the botnet’s C2 architecture was built to maintain resilience and withstand traditional disruption attempts.