Information Density: BleepingComputer – Signal Evidence & AI Readability

BleepingComputer

(https://bleepingcomputer.com) 📸 Data Snapshot: May 28, 2026
Information Density — The Lens

Classify each sentence as substantive or hollow. Grounding markers — numbers, currencies, dates, technical units, named entities — outweigh marketing adjectives. When fluff sits right next to hard evidence, the fluff is forgiven.

Info Density Power-words vs. Substance ratio.
27 Impact Weight: 30 / 100
90% Reputation

BleepingComputer exhibits a remarkably high substance-to-fluff ratio. Headings such as ‘Glassworm botnet disrupted after resilient C2 infrastructure takedown’ replace vague power words with specific, technical nouns and actionable verbs. The body text is densely packed with forensic evidence, including specific IP addresses like ‘164.92.88[.]210’ and mentions of ‘Solana blockchain transactions.’ Marketing fluff is restricted almost entirely to the peripheral ‘Deals’ section, where phrases like ‘grocery routine’s easiest upgrade’ appear, but these do not dilute the primary news reporting.

Information Density is read straight from the body copy: how much of the text carries grounded, checkable substance versus hollow filler. Below is the clean text the engine analyzed, then the industry’s known generic-claim patterns to weigh it against.

📝 The Narrative — clean text per page (the substance-vs-filler signal)
HOMEPAGE (https://bleepingcomputer.com) BleepingComputer | Cybersecurity, Technology News and Support
[IMG: Glassworm botnet disrupted after resilient C2 infrastructure takedown]

[H4] Glassworm botnet disrupted after resilient C2 infrastructure takedown

[IMG: CISA gives feds 4 days to patch actively exploited cPanel plugin flaw]

[H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

[IMG: Windows 11 KB5089573 update released with performance improvements]

[H4] Windows 11 KB5089573 update released with performance improvements

[IMG: Charter confirms data breach after ShinyHunters extortion threat]

[H4] Charter confirms data breach after ShinyHunters extortion threat

[IMG: Glassworm botnet disrupted after resilient C2 infrastructure takedown]

[H4] Glassworm botnet disrupted after resilient C2 infrastructure takedown

[IMG: CISA gives feds 4 days to patch actively exploited cPanel plugin flaw]

[H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

[IMG: Windows 11 KB5089573 update released with performance improvements]

[H4] Windows 11 KB5089573 update released with performance improvements

[IMG: Charter confirms data breach after ShinyHunters extortion threat]

[H4] Charter confirms data breach after ShinyHunters extortion threat

[IMG: ThreatLocker]

Latest Articles

[IMG: Hacker bitcoin]

Security

[H4] GPU mining malware spreads via SEO poisoning, AI chatbots
Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations.
Ionut Ilascu May 27, 2026
05:31 PM
[IMG: Comment Count]
0

[IMG: CompTIA]

Deals

[H4] This CompTIA IT learning path is only $40 through 6/14
Ready to stop guessing your way through IT learning? Get The Complete 2026 CompTIA Certification Training Bundle for just $39.99 with code SAVE20 through June 14.
BleepingComputer Deals May 27, 2026
02:07 PM
[IMG: Comment Count]
0

[IMG: Push Security]

[H4] Browser & Identity Attacks Matrix: Map your exposure to 51 identity attack techniques [Free Resource]
Check out the open-source matrix for browser-based attack techniques. AiTM phishing, ClickFix, device code phishing, ConsentFix, malicious browser extensions — Push Security's Browser & Identity Attacks Matrix maps every technique in one open-source framework.
Push Security Sponsorship

[IMG: Can you enforce strong Active Directory password rules without frustrating users?]

Security

[H4] Can you enforce strong Active Directory password rules without frustrating users?
Strong Active Directory passwords don't have to come at the expense of usability. Specops Software explains how passphrases, breached password protection, and self-service resets can improve security without frustrating users.
Specops Software May 27, 2026
10:00 AM
[IMG: Comment Count]
0

[IMG: GlassWorm]

Security

[H4] Glassworm botnet disrupted after resilient C2 infrastructure takedown
The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network.
Ionut Ilascu May 27, 2026
09:28 AM
[IMG: Comment Count]
0

[IMG: FBI]

Security

[H4] FBI warns of in-person data theft attacks from extortion gang
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks.
Sergiu Gatlan May 27, 2026
07:51 AM
[IMG: Comment Count]
0

[IMG: Sam]

Deals

[H4] Your grocery routine’s easiest upgrade is a Sam’s Club membership for just $25
Buying in bulk gets the attention, but convenience is what keeps people coming back. A 1-year Sam's Club Membership for $25 (MSRP $60) makes it easy to test the theory—and a surprisingly practical case for rethinking how you shop.
BleepingComputer Deals May 27, 2026
07:12 AM
[IMG: Comment Count]
0

[IMG: cPanel]

Security

[H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks.
Sergiu Gatlan May 27, 2026
06:06 AM
[IMG: Comment Count]
0

[IMG: Law enforcement arrest]

Security

[H4] Dutch police arrests suspect linked to Ajax football club hack
The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year.
Sergiu Gatlan May 27, 2026
05:09 AM
[IMG: Comment Count]
0

[IMG: Windows 11]

Microsoft

[H4] Windows 11 KB5089573 update released with performance improvements
Microsoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements.
Sergiu Gatlan May 27, 2026
04:33 AM
[IMG: Comment Count]
1

[IMG: Hacker]

Security

[H4] KnowledgeDeliver flaw exploited as a zero-day to install web shells
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.
Ionut Ilascu May 26, 2026
04:07 PM
[IMG: Comment Count]
0

[IMG: Charter Communications]

Security

[H4] Charter confirms data breach after ShinyHunters extortion threat
U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
Lawrence Abrams May 26, 2026
03:46 PM
[IMG: Comment Count]
2

[IMG: Cybersecurity ethical hacking penetration testing]

Deals

[H4] Nine ethical hacking & penetration testing courses for $30
Breaking into cybersecurity can feel overwhelming, as there are many tools to learn and skills to focus on. The All-in-One Ethical Hacking & Penetration Testing Bundle provides a structured way to get started in cybersecurity, and it is available for a one-time payment of $29.99 (regularly $180).
BleepingComputer Deals May 26, 2026
02:11 PM
[IMG: Comment Count]
0

[IMG: How Varonis Atlas integrates Claude Compliance API for AI governance]

Security

[H4] How Varonis Atlas integrates Claude Compliance API for AI governance
AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance.
Varonis May 26, 2026
10:01 AM
[IMG: Comment Count]
0

[IMG: Microsoft Defender for Endpoint]

Microsoft, Security

[H4] Microsoft Defender can now automatically isolate hacked endpoints
Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network.
Sergiu Gatlan May 26, 2026
08:19 AM
[IMG: Comment Count]
0

[IMG: Automation]

Security

[H4] Webinar: Too many tools are slowing network incident response
IT teams often need to jump between monitoring dashboards, infrastructure tools, ticketing systems, and communication platforms during network incidents. This webinar explores how automation and AI-assisted workflows can help reduce manual coordination and improve incident response times.
BleepingComputer May 26, 2026
08:16 AM
[IMG: Comment Count]
0

[IMG: This lifetime PDF editor is just $65 with code SAVE5 through 5/31]

Deals

[H4] This lifetime PDF editor is just $65 with code SAVE5 through 5/31
PDFs have a ability to turn simple tasks into frustrating experiences. Need to edit a sentence? Different app. Convert a file? Different app. Sign something? Another app. UPDF changes that by being able to complete most PDF tasks in one application, and it's available for a one-time price of $64.97 (MSRP: $149.99) through May 31.
BleepingComputer Deals May 26, 2026
07:12 AM
[IMG: Comment Count]
0

[IMG: Drupal]

Security

[H4] CISA orders feds to patch actively exploited Drupal vulnerability
CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited.
Sergiu Gatlan May 26, 2026
04:46 AM
[IMG: Comment Count]
0

[IMG: Windows Server]

Microsoft

[H4] Microsoft: Domain Controller lookup may fail on Windows Server 2016
Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update.
Sergiu Gatlan May 26, 2026
03:41 AM
[IMG: Comment Count]
0

[IMG: 7-Eleven]

Security

[H4] 7-Eleven data breach exposes personal information of 185,000 people
The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned.
Sergiu Gatlan May 26, 2026
03:01 AM
[IMG: Comment Count]
0

[IMG: ClaudeChats]

Artificial Intelligence, Software

[H4] Anthropic’s restricted Claude Mythos model may be coming to Claude Code
Anthropic appears to be preparing for the public rollout of the Mythos model, which was announced in April as a restricted model that poses major security risks to private and public software.
Mayank Parmar May 25, 2026
01:07 PM
[IMG: Comment Count]
0

1 2 3 4 5
View More

[IMG: ThreatLocker]

Upcoming Webinar
[IMG: Webinar]

Popular Stories

[IMG: Microsoft 365 phishing]

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

[IMG: ClaudeChats]

Anthropic’s restricted Claude Mythos model may be coming to Claude Code

[IMG: Microsoft Defender for Endpoint]

Microsoft Defender can now automatically isolate hacked endpoints

Sponsor Posts

[IMG: AI is a data-breach time bomb: Read the new report]

AI is a data-breach time bomb: Read the new report

[IMG: 33% Rise in Healthcare Credential Theft in 2025: What you need to know]

33% Rise in Healthcare Credential Theft in 2025: What you need to know

[IMG: Protect Your Business from Ecommerce Fraud]

Protect Your Business from Ecommerce Fraud

[IMG: Overdue a password health-check? Audit your Active Directory for free]

Overdue a password health-check? Audit your Active Directory for free

Upcoming Webinar

[IMG: Webinar]
10910 chars
SUB-PAGE (https://bleepingcomputer.com/news/security/) News in the Security category
[IMG: ThreatLocker]

HomeNews in the Security category

News in the Security category

[IMG: Hacker bitcoin]

[H4] GPU mining malware spreads via SEO poisoning, AI chatbots
Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations.
Ionut Ilascu May 27, 2026
05:31 PM
[IMG: Comment Count]
0

[IMG: Can you enforce strong Active Directory password rules without frustrating users?]

[H4] Can you enforce strong Active Directory password rules without frustrating users?
Strong Active Directory passwords don't have to come at the expense of usability. Specops Software explains how passphrases, breached password protection, and self-service resets can improve security without frustrating users.
Specops Software May 27, 2026
10:00 AM
[IMG: Comment Count]
0

[IMG: Push Security]

[H4] Browser & Identity Attacks Matrix: Map your exposure to 51 identity attack techniques [Free Resource]
Check out the open-source matrix for browser-based attack techniques. AiTM phishing, ClickFix, device code phishing, ConsentFix, malicious browser extensions — Push Security's Browser & Identity Attacks Matrix maps every technique in one open-source framework.
Push Security Sponsorship

[IMG: GlassWorm]

[H4] Glassworm botnet disrupted after resilient C2 infrastructure takedown
The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network.
Ionut Ilascu May 27, 2026
09:28 AM
[IMG: Comment Count]
0

[IMG: FBI]

[H4] FBI warns of in-person data theft attacks from extortion gang
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks.
Sergiu Gatlan May 27, 2026
07:51 AM
[IMG: Comment Count]
0

[IMG: cPanel]

[H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks.
Sergiu Gatlan May 27, 2026
06:06 AM
[IMG: Comment Count]
0

[IMG: Law enforcement arrest]

[H4] Dutch police arrests suspect linked to Ajax football club hack
The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year.
Sergiu Gatlan May 27, 2026
05:09 AM
[IMG: Comment Count]
0

[IMG: Hacker]

[H4] KnowledgeDeliver flaw exploited as a zero-day to install web shells
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.
Ionut Ilascu May 26, 2026
04:07 PM
[IMG: Comment Count]
0

[IMG: Charter Communications]

[H4] Charter confirms data breach after ShinyHunters extortion threat
U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.
Lawrence Abrams May 26, 2026
03:46 PM
[IMG: Comment Count]
2

[IMG: How Varonis Atlas integrates Claude Compliance API for AI governance]

[H4] How Varonis Atlas integrates Claude Compliance API for AI governance
AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance.
Varonis May 26, 2026
10:01 AM
[IMG: Comment Count]
0

[IMG: Microsoft Defender for Endpoint]

[H4] Microsoft Defender can now automatically isolate hacked endpoints
Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network.
Sergiu Gatlan May 26, 2026
08:19 AM
[IMG: Comment Count]
0

[IMG: Automation]

[H4] Webinar: Too many tools are slowing network incident response
IT teams often need to jump between monitoring dashboards, infrastructure tools, ticketing systems, and communication platforms during network incidents. This webinar explores how automation and AI-assisted workflows can help reduce manual coordination and improve incident response times.
BleepingComputer May 26, 2026
08:16 AM
[IMG: Comment Count]
0

[IMG: Drupal]

[H4] CISA orders feds to patch actively exploited Drupal vulnerability
CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited.
Sergiu Gatlan May 26, 2026
04:46 AM
[IMG: Comment Count]
0

[IMG: 7-Eleven]

[H4] 7-Eleven data breach exposes personal information of 185,000 people
The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned.
Sergiu Gatlan May 26, 2026
03:01 AM
[IMG: Comment Count]
0

[IMG: Microsoft 365 phishing]

[H4] FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).
Lawrence Abrams May 25, 2026
08:45 AM
[IMG: Comment Count]
0

[IMG: Ghost CMS]

[H4] Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.
Bill Toulas May 24, 2026
10:12 AM
[IMG: Comment Count]
2

[IMG: Hand data data leak hacker]

[H4] Laravel Lang packages hijacked to deploy credential-stealing malware
A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages.
Lawrence Abrams May 23, 2026
04:48 PM
[IMG: Comment Count]
0

[IMG: FIOD]

[H4] Netherlands seizes 800 servers of hosting firm enabling cyberattacks
Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns.
Bill Toulas May 22, 2026
01:24 PM
[IMG: Comment Count]
1

[IMG: Hackers]

[H4] Former US execs plead guilty to aiding tech support scammers
Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide.
Sergiu Gatlan May 22, 2026
11:32 AM
[IMG: Comment Count]
0

[IMG: Trend Micro]

[H4] Trend Micro warns of Apex One zero-day exploited in the wild
Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems.
Sergiu Gatlan May 22, 2026
09:39 AM
[IMG: Comment Count]
0

[IMG: Drupal]

[H4] Drupal: Critical SQL injection flaw now targeted in attacks
Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week.
Bill Toulas May 22, 2026
09:14 AM
[IMG: Comment Count]
1

1 2 3 4 5

[IMG: ThreatLocker]

Upcoming Webinar
[IMG: Webinar]

Popular Stories

[IMG: Microsoft 365 phishing]

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

[IMG: ClaudeChats]

Anthropic’s restricted Claude Mythos model may be coming to Claude Code

[IMG: Microsoft Defender for Endpoint]

Microsoft Defender can now automatically isolate hacked endpoints

Upcoming Webinar

[IMG: Webinar]
8518 chars
SUB-PAGE (https://bleepingcomputer.com/author/sergiu-gatlan/) Viewing the profile for Sergiu Gatlan
HomeViewing author profile for Sergiu Gatlan

[H2] Sergiu Gatlan

Forum Profile:serghei

Get in touch:

[IMG: Author Photo]

[H5] Author Bio
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Sergiu Gatlan
News
Virus Removal Guides
Tutorials

News

1 2 3 4 5

[IMG: FBI warns of in-person data theft attacks from extortion gang Image]

[H4] FBI warns of in-person data theft attacks from extortion gang
The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks.
Sergiu Gatlan May 27, 2026
07:51 AM
[IMG: Comment Count]
0

[IMG: CISA gives feds 4 days to patch actively exploited cPanel plugin flaw Image]

[H4] CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks.
Sergiu Gatlan May 27, 2026
06:06 AM
[IMG: Comment Count]
0

[IMG: Dutch police arrests suspect linked to Ajax football club hack Image]

[H4] Dutch police arrests suspect linked to Ajax football club hack
The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year.
Sergiu Gatlan May 27, 2026
05:09 AM
[IMG: Comment Count]
0

[IMG: Windows 11 KB5089573 update released with performance improvements Image]

[H4] Windows 11 KB5089573 update released with performance improvements
Microsoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements.
Sergiu Gatlan May 27, 2026
04:33 AM
[IMG: Comment Count]
1

[IMG: Microsoft Defender can now automatically isolate hacked endpoints Image]

[H4] Microsoft Defender can now automatically isolate hacked endpoints
Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network.
Sergiu Gatlan May 26, 2026
08:19 AM
[IMG: Comment Count]
0

[IMG: CISA orders feds to patch actively exploited Drupal vulnerability Image]

[H4] CISA orders feds to patch actively exploited Drupal vulnerability
CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited.
Sergiu Gatlan May 26, 2026
04:46 AM
[IMG: Comment Count]
0

[IMG: Microsoft: Domain Controller lookup may fail on Windows Server 2016 Image]

[H4] Microsoft: Domain Controller lookup may fail on Windows Server 2016
Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update.
Sergiu Gatlan May 26, 2026
03:41 AM
[IMG: Comment Count]
0

[IMG: 7-Eleven data breach exposes personal information of 185,000 people Image]

[H4] 7-Eleven data breach exposes personal information of 185,000 people
The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned.
Sergiu Gatlan May 26, 2026
03:01 AM
[IMG: Comment Count]
0

[IMG: Former US execs plead guilty to aiding tech support scammers Image]

[H4] Former US execs plead guilty to aiding tech support scammers
Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide.
Sergiu Gatlan May 22, 2026
11:32 AM
[IMG: Comment Count]
0

[IMG: Trend Micro warns of Apex One zero-day exploited in the wild Image]

[H4] Trend Micro warns of Apex One zero-day exploited in the wild
Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems.
Sergiu Gatlan May 22, 2026
09:39 AM
[IMG: Comment Count]
0

[IMG: Ubiquiti patches three max severity UniFi OS vulnerabilities Image]

[H4] Ubiquiti patches three max severity UniFi OS vulnerabilities
Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS that can be exploited by remote attackers without privileges.
Sergiu Gatlan May 22, 2026
08:00 AM
[IMG: Comment Count]
2

[IMG: US and Canada arrest and charge suspected Kimwolf botnet admin Image]

[H4] US and Canada arrest and charge suspected Kimwolf botnet admin
U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide.
Sergiu Gatlan May 22, 2026
05:01 AM
[IMG: Comment Count]
0

[IMG: Apple blocked over $11 billion in App Store fraud in 6 years Image]

[H4] Apple blocked over $11 billion in App Store fraud in 6 years
Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone.
Sergiu Gatlan May 21, 2026
11:11 AM
[IMG: Comment Count]
1

[IMG: Max severity Cisco Secure Workload flaw gives Site Admin privileges Image]

[H4] Max severity Cisco Secure Workload flaw gives Site Admin privileges
Cisco has released security updates to address a maximum-severity vulnerability in Secure Workload that allows attackers to gain Site Admin privileges.
Sergiu Gatlan May 21, 2026
09:58 AM
[IMG: Comment Count]
0

[IMG: Microsoft warns of new Defender zero-days exploited in attacks Image]

[H4] Microsoft warns of new Defender zero-days exploited in attacks
On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks.
Sergiu Gatlan May 21, 2026
03:49 AM
[IMG: Comment Count]
0

Sergiu Gatlan
News
Virus Removal Guides
Tutorials
6464 chars
SUB-PAGE (https://bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/) Glassworm botnet disrupted after resilient C2 infrastructure takedown
[IMG: ThreatLocker]

HomeNewsSecurityGlassworm botnet disrupted after resilient C2 infrastructure takedown

[H1] Glassworm botnet disrupted after resilient C2 infrastructure takedown

By
[H6] Ionut Ilascu

May 27, 2026
09:28 AM
0

[IMG: Glassworm botnet disrupted after resilient C2 infrastructure takedown]

The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network.

​In a coordinated operation conducted  yesterday, CrowdStrike, Google, and The Shadowserver Foundation cut off the botnet operators’ access to four distinct command-and-control (C2) channels designed to resist conventional disruption efforts.

Glassworm campaigns have been ongoing since October 2025 and initially targeted developers with malicious OpenVSX and Microsoft VS Code extensions that stole cryptocurrency wallets and developer credentials.

Later attack waves extended to GitHub repositories and npm packages, with one campaign in March impacting more than 400 software artifacts.

In a more recent attack, Glassworm operators planted dozens of dormant extensions on OpenVSX that would activate the malicious component after an update.

One reason the Glassworm threat has survived this long is its C2 infrastructure, which relies on non-traditional communication channels that are difficult to take down.

“The combination of blockchain, peer-to-peer, and legitimate web services as resolution layers was designed to be resilient against takedowns — a dynamic front protecting the actual C2 servers behind multiple layers of indirection,” CrowdStrike notes.

The researchers say that “Glassworm's operators built their infrastructure for resilience,” and taking down the botnet required hitting the four C2 channels simultaneously:

Solana blockchain: C2 server addresses are encoded in the memo fields of blockchain transactions, creating an immutable, publicly accessible dead drop that cannot be taken offline by conventional means.
BitTorrent Distributed Hash Table (DHT): The GlasswormRAT queries the BitTorrent peer-to-peer network for configuration data stored against hardcoded public keys, leveraging a global decentralized network with no single point of failure.
Public calendar service: Glassworm uses Google Calendar event titles as dead-drop locations for Base64-encoded C2 paths.
Direct server connections: Traditional C2 infrastructure hosted on commercial VPS providers served as the final payload delivery mechanism.

Glassworm command-and-control architecturesource: CrowdStrike

​Because of this architecture, disrupting a single channel would have little impact on the Glassworm operation, as communications could shift to another channel, allowing the threat actor to maintain control.

“All four channels had to be disrupted simultaneously in a coordinated effort. As a result, infected machines can no longer receive new instructions or payloads,” CrowdStrike says.

Following the disruption, all machines compromised in a Glassworm attack are beaconing to the IP address 164.92.88[.]210 operated by CrowdStrike.

Organizations are advised to look for this network indicator and take immediate remediation action. Additionally, the researchers have published YARA rules to confirm infections on suspected hosts.

[IMG: article image]

[H2]
The Validation Gap: Automated Pentesting Answers One Question. You Need Six.
Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.This guide covers the 6 surfaces you actually need to validate.
Download Now

[H3] Related Articles:
FBI warns of in-person data theft attacks from extortion gang7-Eleven confirms data breach claimed by the ShinyHunters gangGitHub confirms breach of 3,800 repos via malicious VSCode extensionInside a Crypto Drainer: How to Spot it Before it Empties Your WalletGitHub links repo breach to TanStack npm supply-chain attack

CryptoCurrency
Data Theft
Developer
GlassWorm
Supply Chain
Takedown

[H5] Ionut Ilascu
Ionut Ilascu is a technology writer with a focus on all things cybersecurity. The topics he writes about include malware, vulnerabilities, exploits and security defenses, as well as research and innovation in information security. His work has been published by Bitdefender, Netgear, The Security Ledger and Softpedia.

[H5] Post a Comment Community Rules

[H6] You need to login in order to post a comment

Not a member yet? Register Now

[H3] You may also like:

[IMG: ThreatLocker]

Upcoming Webinar
[IMG: Webinar]

Popular Stories

[IMG: Microsoft 365 phishing]

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

[IMG: ClaudeChats]

Anthropic’s restricted Claude Mythos model may be coming to Claude Code

[IMG: Microsoft Defender for Endpoint]

Microsoft Defender can now automatically isolate hacked endpoints

Sponsor Posts

[IMG: Protect Your Business from Ecommerce Fraud]

Protect Your Business from Ecommerce Fraud

[IMG: AI is a data-breach time bomb: Read the new report]

AI is a data-breach time bomb: Read the new report

[IMG: 33% Rise in Healthcare Credential Theft in 2025: What you need to know]

33% Rise in Healthcare Credential Theft in 2025: What you need to know

[IMG: Overdue a password health-check? Audit your Active Directory for free]

Overdue a password health-check? Audit your Active Directory for free

Upcoming Webinar

[IMG: Webinar]
5893 chars
🧭 Industry Context — common generic-claim patterns in Media, News & Publishing to weigh the text against
Generic Claims: trusted news source, unbiased reporting, the truth, delivered, journalism that matters, breaking news first, award-winning journalism…
Red Flags: no named editorial staff, sponsored content without clear labelling, no corrections or complaints policy, ownership and funding not disclosed, aggregated content presented as original reporting, no distinction between news and opinion…
Semantic Drift Patterns: claims editorial independence but content is sponsored, claims fact-checked but no corrections policy visible, homepage says investigative but content is aggregated wire stories, claims community voice but no local reporting staff…
Proof Expectations: named journalists and editorial staff, published editorial standards and ethics code, corrections and complaints policy, ownership and funding transparency, press council or regulatory membership, advertising and editorial separation policy…