The four C&C channels used by GlassWorm, the botnet targeting open source software developers, have been disrupted.
Microsoft has had a VS Code extension for a long time, and it finally came back to bite them.
A single developer. One poisoned extension. Five supply chain surfaces compromised in 48 hours. And a threat group claiming their tool was built by Claude.On May 20, 2026, GitHub confirmed Opens a new ...