Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical vulnerability in the marimo Python notebook platform, tracked as CVE-2026-39987, has been actively exploited to deploy a new variant of NKAbuse malware. The flaw allows for remote code execution without authentication, enabling attackers to leverage Hugging Face Spaces for malware distrib...
A new CVSS 10.0 vulnerability, CVE-2026-29000, was published on March 4, 2026, allowing attackers to bypass authentication in the pac4j-jwt library, enabling impersonation of any user, including administrators. This vulnerability poses a significant risk to applications using this library, as it req...
Security Operations Centers (SOCs) are facing significant alert fatigue, with an average of 2,992 security alerts generated daily, leading to 63% going unaddressed. This phenomenon, akin to alarm fatigue in healthcare, results in analysts missing critical threats due to overwhelming volumes of alert...