CrowdStrike, Google, and Shadowserver dismantled GlassWorm's four-layer C2 infrastructure while Google confirmed the first real-world AI-discovered zero-day exploit. Plus: a critical host-header flaw in the Starlette framework threatens hundreds of millions of AI agent deployments.
Audio is available on Spreaker — see link below.
GlassWorm is down. CrowdStrike, Google, and Shadowserver simultaneously dismantled all four command-and-control layers of one of the most technically elaborate supply chain campaigns seen this year, ending an operation that had quietly poisoned more than three hundred GitHub repositories since early twenty twenty-five.
Separately, Google documented the first confirmed case of a frontier large language model finding and exploiting a zero-day vulnerability in the wild. The target was a popular web administration tool.
There's a critical vulnerability in Starlette that deserves attention. CVE-2026-48710 affects a framework downloaded three hundred twenty-five million times weekly, underpinning FastAPI, vLLM, and LiteLLM deployments globally.
The broader context behind all three of these developments is a shift in attacker tempo that changes the remediation calculus entirely. In twenty twenty-two, the median time from vulnerability disclosure to active exploitation was roughly nine months.
Chinese and North Korean state-sponsored groups are running what amounts to industrial-scale AI vulnerability hunting across routers and corporate networks. Russian operators are developing self-rewriting malware that mutates to evade detection.
What to watch next: whether isolated GlassWorm infections re-establish contact through undisclosed backup channels, how quickly Starlette patches reach production AI deployments, and whether the confirmed AI zero-day case prompts any acceleration in defender-side logic-flaw tooling. Those are the three metrics that will tell you whether the gap is stabilizing or widening.
Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.