daily cyber × ai intelligence

index

tagged

[xworm]

2 editions · 2 items

August 13, 2026

  • A new "SaassyCode" campaign is pushing malicious VS Code extensions: Nextron's scanner flagged "Trello Board" (TrelloWorks.trello-board), which downloads and runs a BAT loader on startup, sets scheduled-task persistence, and injects shellcode into trusted Windows processes — part of the same wave of Marketplace abuse that has also carried XWorm, per Knostic's analysis. · Threat Activity

in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM

August 12, 2026

  • A threat actor keeps pushing XWorm-laden extensions to the VS Code Marketplace. One activated at startup, claimed it needed elevated permissions to "sync board data securely," relaunched VS Code as admin, then added Defender exclusions and pulled a PowerShell stager to drop a fake svchost.exe (Nextron gist). · Threat Activity

in When the AI Is the One Finding the Zero-Days