* [Blog](https://origin-researchcenter.paloaltonetworks.com/blog) * [Security Operations](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/) * Supply Chain Under Siege:... # Supply Chain Under Siege: GlassWorm's Native Rust Loaders Target VS Code [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fglassworm-goes-native-rust-loader-vscode-openvsx%2F) [](https://twitter.com/share?text=Supply+Chain+Under+Siege%3A+GlassWorm%E2%80%99s+Native+Rust+Loaders+Target+VS+Code&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fglassworm-goes-native-rust-loader-vscode-openvsx%2F) [](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Forigin-researchcenter.paloaltonetworks.com%2Fblog%2Fsecurity-operations%2Fglassworm-goes-native-rust-loader-vscode-openvsx%2F&title=Supply+Chain+Under+Siege%3A+GlassWorm%E2%80%99s+Native+Rust+Loaders+Target+VS+Code&summary=&source=) [](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/glassworm-goes-native-rust-loader-vscode-openvsx/&ts=markdown) \[\](mailto:?subject=Supply Chain Under Siege: GlassWorm’s Native Rust Loaders Target VS Code) Link copied By [Lotan Sery](https://www.paloaltonetworks.com/blog/author/lotan-sery/?ts=markdown "Posts by Lotan Sery") Oct 09, 2026 5 minutes [AES](https://www.paloaltonetworks.com/blog/tag/aes/?ts=markdown) [Agentic Endpoint Security](https://www.paloaltonetworks.com/blog/tag/agentic-endpoint-security/?ts=markdown) [Cortex XDR](https://www.paloaltonetworks.com/blog/tag/cortex-xdr/?ts=markdown) [Koi](https://www.paloaltonetworks.com/blog/tag/koi/?ts=markdown) **Originally published December 10, 2025** **Editor's Note:** This article was originally published by Koi Security on December 10, 2025. Following Palo Alto Networks' acquisition of Koi Security, this research has been migrated to the Palo Alto Networks Threat Research hub. The findings below detail historical observations from the November 2025 GlassWorm campaign wave. **Key Takeaways** * **Shift to Compiled Loaders:** GlassWorm abandoned invisible Unicode character obfuscation in favor of compiled native Rust binaries (.node Node.js addons) to complicate static analysis and reverse engineering. * **Dual-Marketplace Targeting:** The threat actor expanded beyond the OpenVSX Registry to target Microsoft's official Visual Studio Code Marketplace. * **Typosquatting \& Update Poisoning:** Malicious extensions initialised with benign functional code to establish downloads before pushing update releases containing native loaders. * **Resilient C2 Infrastructure:** The campaign maintained its core Solana blockchain command-and-control (C2) infrastructure and Google Calendar fallback mechanisms from prior waves. ## Overview of the November 2025 Wave The GlassWorm campaign resurfaced in late November 2025. Following initial public disclosures in October 2025, which observed over 45,000 infected machines, the campaign briefly paused. On November 22, 2025, activity resumed when an associated Solana wallet executed new transactions pointing to a refreshed C2 IP structure. Within days, malicious developer extensions appeared across both the OpenVSX Registry and Microsoft's official Visual Studio Code Marketplace. While the fundamental attack chain and underlying Solana C2 infrastructure remained identical to previous iterations, the actor overhauled their delivery mechanism to evade detection. ## Shift from Unicode Obfuscation to Native Binaries In earlier campaign waves, GlassWorm relied on steganographic techniques using invisible Unicode characters embedded in JavaScript files to hide payload staging code. In the November 2025 wave, the threat actor replaced invisible Unicode obfuscation with compiled Rust binaries. All payload handling capabilities---including Solana C2 lookups, payload decryption, and execution---were moved into native .node binaries. To inspect the underlying mechanics, defenders must perform binary reverse engineering on compiled native code rather than decoding high-level JavaScript. ### Case Study: Iconesvscode Impersonation The extension bphpburnsus.iconesvscode on Microsoft's Visual Studio Code Marketplace impersonated the popular vscode-icons extension. * **Version 12.15.0 (Clean):** Delivered legitimate theme functionality consisting of 22,765 lines of JavaScript. * **Versions 12.15.1 and 12.15.2 (Poisoned):** The legitimate codebase was purged and reduced to 33 lines of JavaScript. ![The fake Iconesvscode extension on Koidex](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/10/word-image-369924-1.png) Figure 1: The fake Iconesvscode extension on Koidex ![The real vscode-icons extension on Koidex](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/10/word-image-369924-2.png) Figure 2: The real vscode-icons extension on Koidex The reduced JavaScript acted purely as a loader: it identified the host operating system and executed the corresponding compiled native binary. ![Rust Binary Loader](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/10/word-image-369924-3.jpeg) Figure 3: Rust Binary Loader ### Technical Analysis of Native Implants The native binaries were distributed as Node.js native addons named darwin.node (macOS) and os.node (Windows). ![](https://www.paloaltonetworks.com/blog/wp-content/uploads/2026/10/word-image-369924-4.png) Each implant binary was approximately 2.4 MB in size. Once loaded into memory by Node.js, the binary executed the following sequence: 1. **C2 Resolution via Solana:** Queries the Solana blockchain to dynamically fetch updated C2 configuration data. 2. **Payload Staging:** Connects to remote staging servers to download Base64-encoded, AES-256-CBC encrypted payloads. 3. **Fallback C2 Routing:** If primary C2 queries fail, the binary uses Google Calendar entries as an operational fallback channel. ### Developer Traces in macOS Binaries Compilation artifacts recovered from darwin.node revealed explicit developer directory paths: | /Users/davidioasd/Downloads/rust\_implant/target/release/deps/librust\_implant.dylib /Users/davidioasd/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/http-body-util-0.1.3/src/combinators/collect.rs | |------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| The username string davidioasd matches artifact patterns identified during the October 2025 initial wave, confirming continuity of author and operational infrastructure. ## Defense and Platform Mitigation [Software supply chain threats](https://www.paloaltonetworks.com/cyberpedia/what-is-supply-chain-attack) targeting developer tools leverage trusted ecosystem channels like IDE marketplaces. Security teams must implement [Agentic Endpoint Security](https://www.paloaltonetworks.com/cyberpedia/agentic-endpoint-security)across dependency channels and developer environments. Organizations using[Cortex^®^ Agentic Endpoint Security](https://www.paloaltonetworks.com/cortex/agentic-endpoint-security) can detect unapproved developer tooling, suspicious AI behavior, and anomalous agentic artifacts within employee workstations. ## Indicators of Compromise (IOCs) **Note:** The extension identifiers and infrastructure addresses below reflect historical findings from the November 2025 investigation. Network [IOCs](https://www.paloaltonetworks.com/cyberpedia/indicators-of-compromise-iocs) have been defanged. #### **Malicious Extension Identifiers** | **OpenVSX Registry** | **Microsoft VSCode Marketplace** | |-------------------------------------|----------------------------------------------| | bphpburn.icons-vscode | bphpburnsus.iconesvscode | | clangdcode.clangd-vscode | iconkieftwo.icon-theme-materiall | | csvmech.csv-sql-tsv-rainbow | clangdcode.clangd-vsce | | cweijamysq.sync-settings-vscode | codevsce.codelddb-vscode | | eamodas.shiny-vscode | csvmech.csvrainbow | | flutcode.flutter-extension | cweijamysq.sync-settings-vscode | | iconkief.icon-theme-material | dart-vsc.code-dart | | msjsdreact.react-native-vscode | flutcode.flutter-extension | | saoudrizvsce.claude-dev | klustfix.kluster-code-verify | | saoudrizvsce.claude-devsce | lyywemhan.code-formatter-and-minifier-vscode | | solblanco.svelte-vscode | msjsdreact.react-native-vsce | | svltsweet.svetle-for-cursor | prettier-vsc.vsce-prettier | | tailwind-nuxt.tailwindcss-for-react | prisma-inc.prisma-studio-assistance | | vitalik.solidity | redmat.vscode-quarkus-pro | | yamlcode.yaml-vscode-extension | saoudrizvsce.claude-devsce | | | solblanco.svetle-vsce | | | vims-vsce.vscode-vim | | | vsceue.volar-vscode | | | yamlcode.yaml-vscode-extension | ### Rust Implants (SHA-256) **macOS (darwin.node):** * 026873b940176d103d45b41c9fba73f14cfcaca60e3117be81d2eadef85a4d17 * 9bd105ce732218f30719fd69d4555967b362d37f4f6aec04741c18aaa7411a73 * fb07743d139f72fca4616b01308f1f705f02fda72988027bc68e9316655eadda **Windows (os.node):** * cbb3f830731fe2c9194f7fe5aa55479cffdae184039b0df078b1394209d7a49f * 29875e74f033c819c1acab58ef08bc35646aab5f4a2747ee0933ca41150d7099 * 6ebeb188f3cc3b647c4460c0b8e41b75d057747c662f4cd7912d77deaccfd2f2 #### **Network Infrastructure** **Command \& Control Infrastructure:** * 217\.69.13\[.\]229 * 45\.76.45\[.\]151 * 45\.32.151\[.\]157 * 107\.191.62\[.\]170 **Exfiltration Servers:** * 104\.238.191\[.\]54 * 108\.61.208\[.\]161 *** ** * ** *** ## Related Blogs ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Partner Integrations](https://www.paloaltonetworks.com/blog/security-operations/category/partner-integrations/?ts=markdown), [Unkategorisiert](https://www.paloaltonetworks.com/blog/category/unkategorisiert/?lang=ja&ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Fighting AI with AI: Palo Alto Networks and Tenzai Collaborate to Defeat Autonomous Threats](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/fighting-ai-with-ai-palo-alto-networks-and-tenzai-collaborate-to-defeat-autonomous-threats/) ### [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Securing the Agentic Endpoint](https://origin-researchcenter.paloaltonetworks.com/blog/2026/02/securing-the-agentic-endpoint/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [AI Security](https://www.paloaltonetworks.com/blog/category/ai-security/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [News and Events](https://www.paloaltonetworks.com/blog/security-operations/category/news-and-events/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### Cortex XDR is the only Certified Leader in AV-Comparatives EPR 7 years in a row](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/cortex-xdr-is-the-only-endpoint-security-market-leader-to-be-certified-by-av-comparatives-7-years-in-a-row/) ### [AI and Cybersecurity](https://www.paloaltonetworks.com/blog/security-operations/category/ai-and-cybersecurity/?ts=markdown), [Announcement](https://www.paloaltonetworks.com/blog/category/announcement/?ts=markdown), [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Must-Read Articles](https://www.paloaltonetworks.com/blog/security-operations/category/must-read-articles/?ts=markdown), [Product Features](https://www.paloaltonetworks.com/blog/security-operations/category/product-features/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown), [Use-Cases](https://www.paloaltonetworks.com/blog/security-operations/category/use-cases/?ts=markdown) [#### Cortex XDR Scores Perfect 100% in SE Labs 2026 Ransomware Test](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/cortex-xdr-scores-perfect-100-in-se-labs-2026-ransomware-test/) ### [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown) [#### Built for Resilience: How Cortex XDR Overcomes Modern SOC Architectural Limitations](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/built-for-resilience-how-cortex-xdr-overcomes-modern-soc-architectural-limitations/) ### [Cybersecurity](https://www.paloaltonetworks.com/blog/category/cybersecurity/?ts=markdown), [Products and Services](https://www.paloaltonetworks.com/blog/category/products-and-services/?ts=markdown) [#### SE Labs Awards Palo Alto Networks the Anti-Tampering Certification](https://origin-researchcenter.paloaltonetworks.com/blog/security-operations/se-labs-awards-palo-alto-networks-the-anti-tampering-certification/) ### Subscribe to Security Operations Blogs! Sign up to receive must-read articles, Playbooks of the Week, new feature announcements, and more. ![spinner](https://origin-researchcenter.paloaltonetworks.com/blog/wp-content/themes/panwblog2023/dist/images/ajax-loader.gif) Sign up Please enter a valid email. By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) and acknowledge our [Privacy Statement](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown). Please look for a confirmation email from us. If you don't receive it in the next 10 minutes, please check your spam folder. This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. {#footer} {#footer} Products and Services * [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security?ts=markdown) * [Secure AI by Design](https://www.paloaltonetworks.com/ai-security?ts=markdown) * [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs?ts=markdown) * [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security?ts=markdown) * [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions?ts=markdown) * [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention?ts=markdown) * [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering?ts=markdown) * [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire?ts=markdown) * [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security?ts=markdown) * [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security?ts=markdown) * [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security?ts=markdown) * [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall?ts=markdown) * [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations?ts=markdown) * [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls?ts=markdown) * [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager?ts=markdown) * [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription?ts=markdown) * [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os?ts=markdown) * [Panorama](https://www.paloaltonetworks.com/network-security/panorama?ts=markdown) * [Secure Access Service Edge](https://www.paloaltonetworks.com/sase?ts=markdown) * [Prisma SASE](https://www.paloaltonetworks.com/sase?ts=markdown) * [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration?ts=markdown) * [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem?ts=markdown) * [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention?ts=markdown) * [Prisma Access](https://www.paloaltonetworks.com/sase/access?ts=markdown) * [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser?ts=markdown) * [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan?ts=markdown) * [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation?ts=markdown) * [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security?ts=markdown) * [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud?ts=markdown) * [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security?ts=markdown) * [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security?ts=markdown) * [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security?ts=markdown) * [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud?ts=markdown) * [AI-Driven SOC](https://www.paloaltonetworks.com/cortex?ts=markdown) * [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam?ts=markdown) * [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr?ts=markdown) * [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar?ts=markdown) * [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse?ts=markdown) * [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response?ts=markdown) * [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam?ts=markdown) * Observability * [Cortex XCOR](https://www.paloaltonetworks.com/cortex/xcor?ts=markdown) * [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira?ts=markdown) * [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management?ts=markdown) * [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management?ts=markdown) * [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager?ts=markdown) * [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance?ts=markdown) * [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management?ts=markdown) * [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic?ts=markdown) * [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management?ts=markdown) * [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance?ts=markdown) * [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery?ts=markdown) * [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access?ts=markdown) * [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42?ts=markdown) * [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense?ts=markdown) * [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses?ts=markdown) * [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy?ts=markdown) * [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence?ts=markdown) * [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond?ts=markdown) Company * [About Us](https://www.paloaltonetworks.com/about-us?ts=markdown) * [Careers](https://jobs.paloaltonetworks.com/en/) * [Contact Us](https://www.paloaltonetworks.com/company/contact-sales?ts=markdown) * [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility?ts=markdown) * [Customers](https://www.paloaltonetworks.com/customers?ts=markdown) * [Investor Relations](https://investors.paloaltonetworks.com/) * [Location](https://www.paloaltonetworks.com/about-us/locations?ts=markdown) * [Newsroom](https://www.paloaltonetworks.com/company/newsroom?ts=markdown) Popular Links * [Blog](https://www.paloaltonetworks.com/blog/?ts=markdown) * [Communities](https://www.paloaltonetworks.com/communities?ts=markdown) * [Content Library](https://www.paloaltonetworks.com/resources?ts=markdown) * [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia?ts=markdown) * [Event Center](https://events.paloaltonetworks.com/) * [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center) * [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z?ts=markdown) * [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications?ts=markdown) * [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure?ts=markdown) * [Sitemap](https://www.paloaltonetworks.com/sitemap?ts=markdown) * [Tech Docs](https://docs.paloaltonetworks.com/) * [Unit 42](https://unit42.paloaltonetworks.com/) * [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd) ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg) * [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy?ts=markdown) * [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center?ts=markdown) * [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use?ts=markdown) * [Documents](https://www.paloaltonetworks.com/legal?ts=markdown) Copyright © 2026 Palo Alto Networks. All Rights Reserved * [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks) * [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector?ts=markdown) * [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/) * [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks) * [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks) * EN Select your language