Glassworm: When Source Code Lies to Your Eyes
A few days ago, the team at Aikido Security published a new report on a campaign they’ve been tracking for almost a year ( read it here ). The threat actor goes by Glassworm, and the technique they use is, I’ll be honest, kind of mind-bending when you first wrap your head around it. The short version: attackers hide malicious payloads inside invisible Unicode characters embedded directly in source…